PT-2026-71887 · Unknown · Openchoreo

CVE-2026-73666

·

Published

2026-08-13

·

Updated

2026-08-14

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenChoreo versions prior to 1.0.4 OpenChoreo versions prior to 1.1.4 OpenChoreo versions prior to 1.2.1
Description The OpenChoreo Backstage backend hardcoded the variables backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true. This configuration exposes the /api/* endpoint without authentication, enabling unauthenticated users to read catalog data, access scaffolder logs, and create or delete catalog locations.
Recommendations Update to version 1.0.4. Update to version 1.1.4. Update to version 1.2.1.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73666
GHSA-V7QX-MQHQ-GRVH

Affected Products

Openchoreo