
🚨Critical - DevGuard Unauthenticated Identity Assertion (CVE-2026-42300) A critical vulnerability in DevGuard allows unauthenticated attackers to bypass authentication using the X-Admin-Token HTTP header. By supplying a target user's UUID in this header, an attacker can gain full administrative control over the organization's DevGuard resources, bypassing the standard Kratos session requirements. 👉 Affected: DevGuard < 1.2.2 | Upgrade to 1.2.2
Post summary
The advisory describes a critical authentication bypass in DevGuard using the X‑Admin‑Token header and recommends an upgrade to version 1.2.2 to remediate the issue.

