CVE-2026-42300 Details
Description
DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware accepts a client-supplied X-Admin-Token HTTP request header and uses its raw string value as the authenticated userID when no Kratos session cookie is present. An unauthenticated attacker who knows or can guess a target user's Kratos identity UUID can issue requests as that user. Where the target user is an organisation admin or owner, this gives the attacker full control over that organisation's DevGuard resources. This vulnerability is fixed in 1.2.2.
A vulnerability in DevGuard's SessionMiddleware prior to version 1.2.2 allows unauthenticated identity assertion. The middleware accepts a client-supplied X-Admin-Token HTTP request header and uses its raw string value as the authenticated user ID when no Kratos session cookie is present. An attacker who knows or can guess a target user's Kratos identity UUID can issue requests as that user. If the target user is an organization admin or owner, the attacker gains full control over that organization's DevGuard resources.
Update DevGuard to version 1.2.2 or later. If an immediate update is not possible, configure a reverse proxy to remove the X-Admin-Token header before forwarding requests to the DevGuard API.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 12, 2026CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/l3montree-dev/devguard/commit/6f38310bf93b2a63df3055038f4da82b1f4e6d9a | [email protected] | Source CodeVendor |
| https://github.com/l3montree-dev/devguard/security/advisories/GHSA-2g9v-7mr5-fgjg | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| l3montree-dev DevGuard | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |
Volerion