๐Ÿ” CVE Alert

CVE-2026-3514

HIGH 7.5

Authentication Bypass in prefecthq/prefect

CVSS Score
7.5
EPSS Score
0.1%
EPSS Percentile
24th

In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware exempts any URL path ending with 'health' or 'ready' from authentication checks. This allows an attacker to create resources with names ending in 'health' or 'ready' and access them without authentication. Affected endpoints include those for variables, flows, work pools, work queues, and deployments. This vulnerability can lead to unauthorized access to sensitive information, such as API keys and database credentials, stored in Prefect Variables.

CWE CWE-863
Vendor prefecthq
Product prefecthq/prefect
Published Jun 2, 2026
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for prefecthq prefecthq/prefect

Be the first to know when new high vulnerabilities affecting prefecthq prefecthq/prefect are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Versions

prefecthq / prefecthq/prefect
unspecified < 3.6.22

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
huntr.com: https://huntr.com/bounties/c540e5e1-f74f-44f4-bfa0-9764ff6daa75 github.com: https://github.com/prefecthq/prefect/commit/e21617125335025b4b27e7d6f0ca028e8e8f3b79