Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 31 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control. | |
| Title | Devtron through 2.2.0 Missing Authorization via webhook API token endpoint | |
| First Time appeared |
Devtron
Devtron devtron |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:devtron:devtron:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Devtron
Devtron devtron |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T21:11:01.297Z
Reserved: 2026-08-31T08:38:43.269Z
Link: CVE-2026-82882
No data.
Status : Received
Published: 2026-08-31T22:17:31.940
Modified: 2026-08-31T22:17:31.940
Link: CVE-2026-82882
No data.
OpenCVE Enrichment
No data.
Weaknesses