PT-2026-93883 · Git+1 · Kubero
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kubero versions prior to 3.1.2
Description
Authentication guards are not applied to the notifications API endpoints, which allows unauthenticated attackers to read webhook secrets and service URLs. This flaw enables the retrieval of stored credentials and the registration of malicious webhooks to intercept pipeline events or suppress alerting by deleting existing configurations.
Recommendations
Update to version 3.1.2 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubero