PT-2026-71926 · Unknown · Openchoreo

CVE-2026-73843

·

Published

2026-08-13

·

Updated

2026-09-10

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenChoreo versions prior to 1.0.2 OpenChoreo versions prior to 1.1.2
Description Management APIs served by internal/cluster-gateway/server.go on the externally reachable agent listener lack authentication. This allows network-reachable attackers to invoke the '/api/proxy/' and '/api/exec/' endpoints, proxy the data-plane Kubernetes API, and execute commands within workload pods in multi-cluster deployments.
Recommendations Update to version 1.0.2. Update to version 1.1.2.

Exploit

Fix

Missing Authorization

Missing Authentication

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73843
GHSA-QH9R-J7RP-4X2M
GO-2026-6362

Affected Products

Openchoreo