Description
Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can retrieve stored credentials and register malicious webhooks to intercept pipeline events or suppress alerting by deleting existing configurations.
Published: 2026-09-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality and Integrity Loss
Action: Immediate Patch
AI Analysis

Impact

Kubero versions up to 3.1.1 do not enforce authentication on the notifications API, allowing attackers to retrieve stored webhook secrets and service URLs. The exposed information includes credentials that could be used to impersonate legitimate webhooks, intercept pipeline events, or delete existing configurations, effectively compromising both confidentiality and integrity of the deployment. The vulnerability is categorized under CWE-306, indicating a failure to check authentication before allowing an operation.

Affected Systems

The impact applies to all installations of Kubero built from the kubero-dev/kubero code base with a version of 3.1.1 or earlier. No specific sub‑version or build is listed, so the entire 3.1.1 release is affected.

Risk and Exploitability

The CVSS score of 9.3 reflects a high severity – an unauthenticated attacker can gain significant knowledge of the system and alter webhook behavior. EPSS indicates the likelihood of exploitation is very low (< 1 %), yet the absence from the CISA KEV catalog suggests no widespread exploitation has been reported to date. An attacker could exploit this via unauthenticated HTTP requests to the /notifications endpoints, provided network reachability to the Kubero instance.

Generated by OpenCVE AI on September 18, 2026 at 06:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kubero to the latest release that implements authentication guards in the notifications API.
  • Apply network segmentation or firewall rules to restrict external access to Kubero’s notification endpoints until the patch is applied.
  • Verify that all notification configurations are revoked or regenerated after patching to eliminate any compromised webhook secrets.

Generated by OpenCVE AI on September 18, 2026 at 06:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Kubero-dev
Kubero-dev kubero
Vendors & Products Kubero-dev
Kubero-dev kubero

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can retrieve stored credentials and register malicious webhooks to intercept pipeline events or suppress alerting by deleting existing configurations.
Title Kubero through 3.1.1 Unauthenticated Notifications API Access
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Kubero-dev Kubero
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:54.668Z

Reserved: 2026-09-16T17:20:11.175Z

Link: CVE-2026-92720

cve-icon Vulnrichment

Updated: 2026-09-17T19:15:38.859Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T18:17:22.990

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-92720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:12:11Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function