Beveiligingsadvies

CVE-2026-82882

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-31 21:11:01
Laatst bijgewerkt 2026-09-02 14:55:30
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control.