PT-2026-71925 · Unknown · Openchoreo
CVE-2026-73842
·
Published
2026-08-13
·
Updated
2026-09-10
CVSS v3.1
9.0
Critical
| Vector | AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenChoreo versions prior to 1.0.3
OpenChoreo versions prior to 1.1.3
OpenChoreo versions prior to 1.2.0-rc.2
Description
The
internal/cluster-gateway/server.go component exposes the '/api/proxy/', '/api/exec/', and '/api/wirelogs/' endpoints on an internal listener without requiring a client certificate or token. This lack of authentication allows any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes.Recommendations
Update to version 1.0.3.
Update to version 1.1.3.
Update to version 1.2.0-rc.2.
Exploit
Fix
Improper Privilege Management
Missing Authentication
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openchoreo