PT-2026-71925 · Unknown · Openchoreo

CVE-2026-73842

·

Published

2026-08-13

·

Updated

2026-09-10

CVSS v3.1

9.0

Critical

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenChoreo versions prior to 1.0.3 OpenChoreo versions prior to 1.1.3 OpenChoreo versions prior to 1.2.0-rc.2
Description The internal/cluster-gateway/server.go component exposes the '/api/proxy/', '/api/exec/', and '/api/wirelogs/' endpoints on an internal listener without requiring a client certificate or token. This lack of authentication allows any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes.
Recommendations Update to version 1.0.3. Update to version 1.1.3. Update to version 1.2.0-rc.2.

Exploit

Fix

Improper Privilege Management

Missing Authentication

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73842
GHSA-RH53-XVX2-J327
GO-2026-6428

Affected Products

Openchoreo