Vulnerability in OpenChoreo Kubernetes Platform Exposes Sensitive APIs
CVE-2026-73842

9CRITICAL

Key Information:

Vendor

Openchoreo

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73842?

In OpenChoreo versions prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, an internal server component exposed several sensitive APIs (/api/proxy/, /api/exec/, and /api/wirelogs/) without the necessary client certificate or token authentication. This allowed any reachable network entity to access and manipulate tenant Kubernetes Secrets, affecting the integrity and confidentiality of workloads. The vulnerability was rectified in subsequent releases, enhancing the security measures of the platform.

Affected Version(s)

openchoreo < 1.0.3 < 1.0.3

openchoreo >= 1.1.0, < 1.1.3 < 1.1.0, 1.1.3

openchoreo >= 1.2.0-rc.1, < 1.2.0-rc.2 < 1.2.0-rc.1, 1.2.0-rc.2

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.