CVE-2026-82882: Devtron-Labs Devtron
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control.
Affected products
- Devtron-Labs Devtron: up to and including 2.2.0
Published 2026-08-31. Last modified 2026-09-08.