PT-2026-82333 · Kubepi · Kubepi
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
KubePi versions prior to 2.0.0
Description
SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, allowing SSO, OIDC, and SAML management operations to be accessed without administrator authorization. This allows unauthorized or low-privileged users to inspect or modify the authentication configuration, potentially leading to account takeover or privilege escalation. Additionally, the SSO connectivity-test function can be used as a server-side request forgery (SSRF) primitive—a technique where an attacker induces the server to make requests to an unintended location. Furthermore, the user list API returns user objects without consistently removing authentication-related fields.
Recommendations
Update to version 2.0.0.
Exploit
Fix
LPE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubepi