Threats Tagged 'cve-2026-42300'
View all threats tagged with 'cve-2026-42300'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-42300'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-42300 is a critical authentication bypass vulnerability in l3montree-dev's DevGuard software versions prior to 1.2.2. The issue arises because the SessionMiddleware accepts a client-supplied X-Admin-Token HTTP header and uses its raw string value as the authenticated userID when no Kratos session cookie is present. An unauthenticated attacker who can guess or know a target user's Kratos identity UUID can impersonate that user. If the targeted user has organization admin or owner privileges, the attacker gains full control over that organization's DevGuard resources. This vulnerability is fixed in version 1.2.2. Join the discussion | CVE Database V5 | 05/12/2026, 17:25:20 UTC Added: 05/12/2026, 18:22:04 UTC |
Showing 1 to 1 of 1 result