Devtron through 2.2.0 fails to enforce authorization...
High severity
Unreviewed
Published
Sep 1, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Aug 31, 2026
Published to the GitHub Advisory Database
Sep 1, 2026
Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and application parameters to retrieve plaintext super-admin JWT tokens for full platform control.
References