PT-2026-71924 · Unknown · Openchoreo
CVE-2026-73841
·
Published
2026-08-13
·
Updated
2026-09-10
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenChoreo versions 1.2.0-rc.1 through 1.2.0
Description
An authorization flaw exists in the
openchoreo-api where the system uses a caller-supplied project query parameter instead of the comp.Spec.Owner.ProjectName to authorize component:exec and wirelogs:view actions. This allows a user with a project-scoped grant to execute commands and read wirelogs from components belonging to other projects within the same namespace. The issue affects the following endpoints:/exec(handled byinternal/openchoreo-api/api/handlers/exec.go)/wirelogs(handled byinternal/openchoreo-api/api/handlers/wirelogs.go)
Recommendations
Update OpenChoreo to version 1.2.0.
Exploit
Fix
Incorrect Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openchoreo