{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/kubero/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kubero:kubero:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-92720"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kubero (\u003c= 3.1.1)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Kubero"],"content_html":"\u003cp\u003eKubero versions up to and including 3.1.1 are affected by an authentication bypass vulnerability (CVE-2026-92720) affecting the notifications API endpoints. This security flaw stems from a failure to enforce authentication guards on API routes responsible for handling notification configurations. An unauthenticated attacker can query these endpoints to retrieve sensitive stored credentials, such as webhook secrets and service URLs, which are often used to integrate Kubero with external messaging or CI/CD platforms. Beyond information disclosure, the lack of access control allows an unauthorized party to register malicious webhooks or delete existing ones. This enables attackers to intercept sensitive pipeline event data or effectively silence security and operational alerts, potentially facilitating persistence or concealing further malicious activity within the Kubernetes-based environment. Defenders should prioritize patching and inspect access logs for abnormal requests to API endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the exposure of sensitive credentials and the potential for persistent interference with CI/CD pipeline visibility. By hijacking notification channels or disabling alerting, attackers can suppress incident response workflows, allowing other malicious actions to go unnoticed. This vulnerability impacts environments running Kubero for automated deployment or monitoring, posing a significant risk to the integrity of the software supply chain and operational monitoring.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Kubero instances to a patched version beyond 3.1.1 immediately to resolve CVE-2026-92720.\u003c/li\u003e\n\u003cli\u003eAudit webhooks and notification configurations within the Kubero platform for any unauthorized entries or suspicious destination URLs.\u003c/li\u003e\n\u003cli\u003eImplement network-level restrictions using Kubernetes NetworkPolicies or Ingress-level authentication (e.g., mTLS or OIDC) to limit access to the Kubero API to authorized internal services only.\u003c/li\u003e\n\u003cli\u003eReview webserver access logs for anomalous, unauthenticated GET or POST requests directed at notification API endpoints that do not originate from known, trusted CI/CD orchestrators.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T19:51:26Z","date_published":"2026-09-16T19:51:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kubero-auth-bypass/","summary":"Kubero versions 3.1.1 and earlier contain an authentication bypass vulnerability in the notifications API, allowing unauthenticated attackers to exfiltrate webhook secrets and manipulate pipeline alerting configurations.","title":"Authentication Bypass in Kubero Notifications API","url":"https://feed.craftedsignal.io/briefs/2026-09-kubero-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Kubero","version":"https://jsonfeed.org/version/1.1"}