CVE-2026-73842 is a critical vulnerability affecting github.com/openchoreo/openchoreo versions >= 1.1.0, < 1.1.3 affecting github.com/openchoreo/openchoreo versions >= 1.2.0-rc.1, < 1.2.0-rc.2 in the OpenChoreo control-plane cluster-gateway, which exposes internal management APIs without caller authentication and permits mutating HTTP methods and reads of Secrets in tenant namespaces. This allows an attacker to read Secrets in any tenant namespace, workloads, and exec into pods across every connected data plane, resulting in Secret disclosure, workload tampering or destruction, and pod command execution inside workload pods via the environment template management API. The vulnerability has a CVSS score of 9.0 and is classified as an authentication bypass flaw with a high attack vector, leading to potential unauthorized access and data breaches. The business impact is significant due to the exposure of sensitive information and the ability to manipulate workloads and execute commands within pods. The affected version range is not explicitly stated in the article, but it is mentioned that the issue has been fixed in versions 1.0.3, 1.1.3, and 1.2.0.
We recommend you to upgrade OpenChoreo to version 1.0.3, 1.1.3 or 1.2.0 depending on your installed branch.[/subscribe_to_unlock_form]
CVE-2026-73842 is a critical vulnerability affecting github.com/openchoreo/openchoreo versions >= 1.1.0, < 1.1.3 affecting github.com/openchoreo/openchoreo versions >= 1.2.0-rc.1, < 1.2.0-rc.2 in the OpenChoreo control-plane cluster-gateway, which exposes internal management APIs without caller authentication and permits mutating HTTP methods and reads of Secrets in tenant namespaces. This allows an attacker to read Secrets in any tenant namespace, workloads, and exec into pods across every connected data plane, resulting in Secret disclosure, workload tampering or destruction, and pod command execution inside workload pods via the environment template management API. The vulnerability has a CVSS score of 9.0 and is classified as an authentication bypass flaw with a high attack vector, leading to potential unauthorized access and data breaches. The business impact is significant due to the exposure of sensitive information and the ability to manipulate workloads and execute commands within pods. The affected version range is not explicitly stated in the article, but it is mentioned that the issue has been fixed in versions 1.0.3, 1.1.3, and 1.2.0.
We recommend you to upgrade OpenChoreo to version 1.0.3, 1.1.3 or 1.2.0 depending on your installed branch.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]