CVE-2026-42300
CRITICALDevGuard: Unauthenticated identity assertion via `X-Admin-Token` header
Title source: cnaDescription
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware accepts a client-supplied X-Admin-Token HTTP request header and uses its raw string value as the authenticated userID when no Kratos session cookie is present. An unauthenticated attacker who knows or can guess a target user's Kratos identity UUID can issue requests as that user. Where the target user is an organisation admin or owner, this gives the attacker full control over that organisation's DevGuard resources. This vulnerability is fixed in 1.2.2.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/l3montree-dev/devguard/security/advisories/GHSA-2g9v-7mr5-fgjg
X_Refsource_Misc x_refsource_misc
https://github.com/l3montree-dev/devguard/commit/6f38310bf93b2a63df3055038f4da82b1f4e6d9a
Scores
CVSS v4
9.3
EPSS
0.0026
EPSS Percentile
16.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-288
Status
published
Products (2)
l3montree-dev/devguard
0 - 1.2.2Go
l3montree-dev/devguard
< 1.2.2
Published
May 12, 2026
Tracked Since
May 13, 2026