Junglewise Threat Intelligence

CVE-2026-7723: Prefect unauthenticated event injection in WebSocket endpoint

CVE-2026-7723 · Severity: high · CVSS 7.3 · Published 2026-05-04

Technologies: PrefectHQ Prefect. Vendors: PyPI.

Executive brief

Prefect is a workflow orchestration platform used to manage and observe data pipelines. A security flaw in its WebSocket endpoint allows unauthorized users to inject events into the system without authentication. This could allow an attacker to disrupt operations, trigger unauthorized workflows, or interfere with the integrity of data pipeline monitoring.

Technical details

An improper authentication vulnerability (CWE-287) exists in the Prefect WebSocket endpoint located at /api/events/in. The flaw allows a remote, unauthenticated attacker to connect to the WebSocket and inject arbitrary events into the Prefect event stream. This occurs due to a failure to enforce authentication checks on this specific endpoint. An attacker can exploit this to manipulate system behavior or monitoring data. The issue is addressed in version 3.6.14 by implementing proper authentication requirements for the affected endpoint.

Affected products

  • PrefectHQ prefect < 3.6.14

Timeline

  • 2026-05-04: disclosed
  • 2026-05-04: advisory
  • 2026-05-04: patched: Fixed in version 3.6.14

References

Related threats