{"api_version":"1","generated_at":"2026-08-14T01:58:47+00:00","cve":"CVE-2026-73842","urls":{"html":"https://cve.report/CVE-2026-73842","api":"https://cve.report/api/cve/CVE-2026-73842.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-73842","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-73842"},"summary":{"title":"OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation","description":"OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-08-13 22:17:29","updated_at":"2026-08-13 22:17:29"},"problem_types":["CWE-269","CWE-306","CWE-862","CWE-269 CWE-269: Improper Privilege Management","CWE-306 CWE-306: Missing Authentication for Critical Function","CWE-862 CWE-862: Missing Authorization"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"9","severity":"CRITICAL","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9,"baseSeverity":"CRITICAL","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9","severity":"CRITICAL","vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/openchoreo/openchoreo/commit/e3da3c63dcf0895c693cb17ce142ef95e959b62a","name":"https://github.com/openchoreo/openchoreo/commit/e3da3c63dcf0895c693cb17ce142ef95e959b62a","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openchoreo/openchoreo/releases/tag/v1.2.0-rc.2","name":"https://github.com/openchoreo/openchoreo/releases/tag/v1.2.0-rc.2","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openchoreo/openchoreo/commit/93e6f10953cfc249af2222ddb6730d4b0a729129","name":"https://github.com/openchoreo/openchoreo/commit/93e6f10953cfc249af2222ddb6730d4b0a729129","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openchoreo/openchoreo/commit/50fcae3f1753fd0ac3ae655a3fc080a761c49c04","name":"https://github.com/openchoreo/openchoreo/commit/50fcae3f1753fd0ac3ae655a3fc080a761c49c04","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openchoreo/openchoreo/security/advisories/GHSA-rh53-xvx2-j327","name":"https://github.com/openchoreo/openchoreo/security/advisories/GHSA-rh53-xvx2-j327","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openchoreo/openchoreo/pull/4256","name":"https://github.com/openchoreo/openchoreo/pull/4256","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openchoreo/openchoreo/pull/4258","name":"https://github.com/openchoreo/openchoreo/pull/4258","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openchoreo/openchoreo/releases/tag/v1.1.3","name":"https://github.com/openchoreo/openchoreo/releases/tag/v1.1.3","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openchoreo/openchoreo/releases/tag/v1.0.3","name":"https://github.com/openchoreo/openchoreo/releases/tag/v1.0.3","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/openchoreo/openchoreo/pull/4259","name":"https://github.com/openchoreo/openchoreo/pull/4259","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73842","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73842","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"openchoreo","product":"openchoreo","version":"affected < 1.0.3","platforms":[]},{"source":"CNA","vendor":"openchoreo","product":"openchoreo","version":"affected >= 1.1.0, < 1.1.3","platforms":[]},{"source":"CNA","vendor":"openchoreo","product":"openchoreo","version":"affected >= 1.2.0-rc.1, < 1.2.0-rc.2","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"openchoreo","vendor":"openchoreo","versions":[{"status":"affected","version":"< 1.0.3"},{"status":"affected","version":">= 1.1.0, < 1.1.3"},{"status":"affected","version":">= 1.2.0-rc.1, < 1.2.0-rc.2"}]}],"descriptions":[{"lang":"en","value":"OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-13T21:59:24.390Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/openchoreo/openchoreo/security/advisories/GHSA-rh53-xvx2-j327","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openchoreo/openchoreo/security/advisories/GHSA-rh53-xvx2-j327"},{"name":"https://github.com/openchoreo/openchoreo/pull/4256","tags":["x_refsource_MISC"],"url":"https://github.com/openchoreo/openchoreo/pull/4256"},{"name":"https://github.com/openchoreo/openchoreo/pull/4258","tags":["x_refsource_MISC"],"url":"https://github.com/openchoreo/openchoreo/pull/4258"},{"name":"https://github.com/openchoreo/openchoreo/pull/4259","tags":["x_refsource_MISC"],"url":"https://github.com/openchoreo/openchoreo/pull/4259"},{"name":"https://github.com/openchoreo/openchoreo/commit/50fcae3f1753fd0ac3ae655a3fc080a761c49c04","tags":["x_refsource_MISC"],"url":"https://github.com/openchoreo/openchoreo/commit/50fcae3f1753fd0ac3ae655a3fc080a761c49c04"},{"name":"https://github.com/openchoreo/openchoreo/commit/93e6f10953cfc249af2222ddb6730d4b0a729129","tags":["x_refsource_MISC"],"url":"https://github.com/openchoreo/openchoreo/commit/93e6f10953cfc249af2222ddb6730d4b0a729129"},{"name":"https://github.com/openchoreo/openchoreo/commit/e3da3c63dcf0895c693cb17ce142ef95e959b62a","tags":["x_refsource_MISC"],"url":"https://github.com/openchoreo/openchoreo/commit/e3da3c63dcf0895c693cb17ce142ef95e959b62a"},{"name":"https://github.com/openchoreo/openchoreo/releases/tag/v1.0.3","tags":["x_refsource_MISC"],"url":"https://github.com/openchoreo/openchoreo/releases/tag/v1.0.3"},{"name":"https://github.com/openchoreo/openchoreo/releases/tag/v1.1.3","tags":["x_refsource_MISC"],"url":"https://github.com/openchoreo/openchoreo/releases/tag/v1.1.3"},{"name":"https://github.com/openchoreo/openchoreo/releases/tag/v1.2.0-rc.2","tags":["x_refsource_MISC"],"url":"https://github.com/openchoreo/openchoreo/releases/tag/v1.2.0-rc.2"}],"source":{"advisory":"GHSA-rh53-xvx2-j327","discovery":"UNKNOWN"},"title":"OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-73842","datePublished":"2026-08-13T21:59:24.390Z","dateReserved":"2026-08-13T17:44:28.642Z","dateUpdated":"2026-08-13T21:59:24.390Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-13 22:17:29","lastModifiedDate":"2026-08-13 22:17:29","problem_types":["CWE-269","CWE-306","CWE-862","CWE-269 CWE-269: Improper Privilege Management","CWE-306 CWE-306: Missing Authentication for Critical Function","CWE-862 CWE-862: Missing Authorization"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9,"baseSeverity":"CRITICAL","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"73842","Ordinal":"1","Title":"OpenChoreo: cluster-gateway internal proxy performs no caller au","CVE":"CVE-2026-73842","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"73842","Ordinal":"1","NoteData":"OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.","Type":"Description","Title":"OpenChoreo: cluster-gateway internal proxy performs no caller au"}]}}}