Authentication Bypass in OpenCost Exposing Cloud Provider Credentials
CVE-2026-67349
Key Information:
Badges
What is CVE-2026-67349?
The OpenCost application prior to version 1.121.0 exhibits significant security vulnerabilities that jeopardize sensitive information. It fails to authenticate requests to the GET /helmValues endpoint, which allows unauthorized access to base64-decoded HELM_VALUES, potentially revealing critical cloud provider credentials. Furthermore, the adminAuthMiddleware is improperly configured, failing to enforce security checks when the ADMIN_TOKEN is not set. This oversight makes it possible for unauthenticated attackers to exploit the system by modifying Google Cloud Platform (GCP) service account keys through the POST /serviceKey endpoint, enabling them to redirect billing calls and potentially causing severe financial repercussions.
Affected Version(s)
opencost 0 < 1.121.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
