CVE-2026-82882

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 22:17

Updated : 2026-09-08 20:18


NVD link : CVE-2026-82882

Mitre link : CVE-2026-82882

CVE.ORG link : CVE-2026-82882


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization