Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
prefecthq prefecthq/prefect — Authentication Bypass in prefecthq/prefect
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H N N 7.5 .0048 39.3 —
AFFECTED
Product Versions Fixed
prefecthq/prefect unspecified – —
TIMELINE
Mar 4 Reserved by @huntr_ai
Jun 2 EXPLOIT PUBLISHED — CVE-2026-3514 (prefecthq/prefect). Public exploit reference added.
Jun 2 Published (CNA: @huntr_ai)
Description
In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware exempts any URL path ending with 'health' or 'ready' from authentication checks. This allows an attacker to create resources with names ending in 'health' or 'ready' and access them without authentication. Affected endpoints include those for variables, flows, work pools, work queues, and deployments. This vulnerability can lead to unauthorized access to sensitive information, such as API keys and database credentials, stored in Prefect Variables.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| March 4, 2026 | Reserved | Reserved by @huntr_ai |
| June 2, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-3514 (prefecthq/prefect). Public exploit reference added. |
| June 2, 2026 | Published | Published (CNA: @huntr_ai) |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| prefecthq | prefecthq/prefect | — | unspecified | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-3514 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.