CVE-2026-3514
In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware exempts any URL path ending with 'health' or 'ready' from authentication checks. This allows an attacker to create resources with names ending in 'health' or 'ready' and access them without authentication. Affected endpoints include those for variables, flows, work pools, work queues, and deployments. This vulnerability can lead to unauthorized access to sensitive information, such as API keys and database credentials, stored in Prefect Variables.
Published:Jun 2, 2026
Last Modified:Jun 3, 2026
EPS:Jun 2, 2026
EPSS Score:0.00083
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Prefect
Product
Prefect
Prefect
Prefect
Vendor
Prefecthq
Product
Prefecthq/prefect
Prefecthq
Prefecthq/prefect
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
