---
id: CVE-2025-62714
title: >-
  Karmada Dashboard is a general-purpose, web-based control panel for Karmada
  which is a multi-cluster management project
summary: >-
  Karmada Dashboard is a general-purpose, web-based control panel for Karmada
  which is a multi-cluster management project. Prior to version 0.2.0, there is
  an authentication bypass vulnerability in the Karmada Dashboard API. The
  backend AP…
severity: none
cwe:
  - CWE-862
published: '2025-10-24'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62714'
references:
  - url: >-
      https://github.com/karmada-io/dashboard/commit/8457b8bb87725e2371a638ca5a255fd2895c70f1
    label: security-advisories@github.com
  - url: >-
      https://github.com/karmada-io/dashboard/commit/d2d04909f25e96b4c20fa6b636c398bd1636ee06
    label: security-advisories@github.com
  - url: 'https://github.com/karmada-io/dashboard/pull/271'
    label: security-advisories@github.com
  - url: 'https://github.com/karmada-io/dashboard/pull/280'
    label: security-advisories@github.com
  - url: 'https://github.com/karmada-io/dashboard/releases/tag/v0.2.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/karmada-io/dashboard/security/advisories/GHSA-5qjg-9mjh-4r92
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00494
epssPercentile: 0.40413
ingestedAt: '2026-10-08T11:31:27.575Z'
---

## Overview

Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not enforce authentication, allowing unauthenticated users to access sensitive cluster information such as Secrets and Services directly. Although the web UI required a valid JWT for access, the API itself remained exposed to direct requests without any authentication checks. Any user or entity with network access to the Karmada Dashboard service could exploit this vulnerability to retrieve sensitive data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
