Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 31 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control. | |
| Title | Devtron through 2.2.0 Missing Authorization via webhook API token endpoint | |
| First Time appeared |
Devtron
Devtron devtron |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:devtron:devtron:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Devtron
Devtron devtron |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T21:11:01.297Z
Reserved: 2026-08-31T08:38:43.269Z
Link: CVE-2026-82882
No data.
Status : Received
Published: 2026-08-31T22:17:31.940
Modified: 2026-08-31T22:17:31.940
Link: CVE-2026-82882
No data.
OpenCVE Enrichment
No data.