GHSA-8wpc-j9q9-j5m2
HIGHCVE-2026-25538This vulnerability exists in Devtron's Attributes API interface, allowing any authenticated user (including low-privileged CI/CD Developers) to obtain the global API Token signing key by accessing the /orchestrator/attributes?key=apiTokenSecret endpoint. After obtaining the key, attackers can forge JWT tokens for arbitrary user identities offline, thereby gaining complete control over the Devtron
- Affected
- <= 2.0.0
- Fixed in
- not stated
- Weakness
- CWE-862
- Published
- 2026-02-04
- Source
- github