PT-2026-71924 · Unknown · Openchoreo

CVE-2026-73841

·

Published

2026-08-13

·

Updated

2026-09-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenChoreo versions 1.2.0-rc.1 through 1.2.0
Description An authorization flaw exists in the openchoreo-api where the system uses a caller-supplied project query parameter instead of the comp.Spec.Owner.ProjectName to authorize component:exec and wirelogs:view actions. This allows a user with a project-scoped grant to execute commands and read wirelogs from components belonging to other projects within the same namespace. The issue affects the following endpoints:
  • /exec (handled by internal/openchoreo-api/api/handlers/exec.go)
  • /wirelogs (handled by internal/openchoreo-api/api/handlers/wirelogs.go)
Recommendations Update OpenChoreo to version 1.2.0.

Exploit

Fix

Incorrect Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73841
GHSA-52GF-6RPQ-FGMX
GO-2026-6358

Affected Products

Openchoreo