Vulnerability in OpenChoreo Kubernetes Platform Exposes Sensitive APIs
CVE-2026-73842
9CRITICAL
What is CVE-2026-73842?
In OpenChoreo versions prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, an internal server component exposed several sensitive APIs (/api/proxy/, /api/exec/, and /api/wirelogs/) without the necessary client certificate or token authentication. This allowed any reachable network entity to access and manipulate tenant Kubernetes Secrets, affecting the integrity and confidentiality of workloads. The vulnerability was rectified in subsequent releases, enhancing the security measures of the platform.
Affected Version(s)
openchoreo < 1.0.3 < 1.0.3
openchoreo >= 1.1.0, < 1.1.3 < 1.1.0, 1.1.3
openchoreo >= 1.2.0-rc.1, < 1.2.0-rc.2 < 1.2.0-rc.1, 1.2.0-rc.2
