CVE-2026-7723 Details
Description
A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of the component WebSocket Endpoint. Executing a manipulation can lead to missing authentication. The attack may be performed from remote. The exploit has been published and may be used. Upgrading to version 3.6.14 is able to address this issue. This patch is called f8afecadf88ea5f73694dafa3a365b9d8fae1ad6. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
A vulnerability exists in PrefectHQ Prefect versions prior to 3.6.14, specifically within the WebSocket endpoint at '/api/events/in'. This flaw allows remote attackers to connect without authentication and inject arbitrary events. The issue arises because the endpoint does not properly enforce authentication, even when the 'PREFECT_SERVER_API_AUTH_STRING' is set. As a result, injected events bypass security measures and can disrupt the application's event handling and automation processes.
Users are advised to upgrade to Prefect version 3.6.14, which addresses this vulnerability by adding the necessary authentication requirements to the WebSocket endpoint.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 4, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/nedlir/f1ab8aa038aafbcc6beeef21fab1d74f | [email protected] | ExploitRemedy |
| https://github.com/PrefectHQ/prefect/ | [email protected] | ProductVendor |
| https://github.com/PrefectHQ/prefect/commit/f8afecadf88ea5f73694dafa3a365b9d8fae1ad6 | [email protected] | |
| https://github.com/PrefectHQ/prefect/pull/20372 | [email protected] | Issue TrackingVendor |
| https://github.com/PrefectHQ/prefect/releases/tag/3.6.14 | [email protected] | Release NotesVendor |
| https://vuldb.com/submit/807256 | [email protected] | Permission Required |
| https://vuldb.com/vuln/360899 | [email protected] | AdvisoryPermission RequiredRemedy |
| https://vuldb.com/vuln/360899/cti | [email protected] | Permission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PrefectHQ prefect | >= 3, < 3.6.14 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | CVE Modified | [email protected] |
| May 4, 2026 | New CVE Received | [email protected] |
Volerion