{"id":"CVE-2026-73843","aliases":["GHSA-qh9r-j7rp-4x2m"],"url":"https://o3.security/vulnerability/CVE-2026-73843","summary":"OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs","details":"OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations, proxy the data-plane Kubernetes API, and execute commands in workload pods in multi-cluster deployments. This issue is fixed in versions 1.0.2 and 1.1.2.","published":"2026-08-13T22:02:41.363Z","modified":"2026-08-15T04:07:21.193243432Z","cvss":{"score":9.6,"severity":"CRITICAL","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/openchoreo/openchoreo/commit/047d80ddc63b4b4b9dd67044d5cffcdbd77685ce","label":"openchoreo/openchoreo@047d80d"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73843.json"},{"type":"FIX","url":"https://github.com/openchoreo/openchoreo/commit/047d80ddc63b4b4b9dd67044d5cffcdbd77685ce"},{"type":"FIX","url":"https://github.com/openchoreo/openchoreo/commit/0aa0ffe1623bd8eb4235cb2a5854336695953c3a"},{"type":"FIX","url":"https://github.com/openchoreo/openchoreo/commit/b42eeb0f5dce95195a9781d7c5a1fe9e38f5da8f"},{"type":"FIX","url":"https://github.com/openchoreo/openchoreo/pull/4122"},{"type":"WEB","url":"https://github.com/openchoreo/openchoreo/releases/tag/v1.0.2"},{"type":"WEB","url":"https://github.com/openchoreo/openchoreo/releases/tag/v1.1.2"},{"type":"ADVISORY","url":"https://github.com/openchoreo/openchoreo/security/advisories/GHSA-qh9r-j7rp-4x2m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73843"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-15T04:07:21.193243432Z"}}