CVE-2026-73841
Received Received - Intake

Command Injection in OpenChoreo Kubernetes Platform

Vulnerability report for CVE-2026-73841, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: GitHub, Inc.

Description

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in and read wirelogs from components owned by other projects in the same namespace. This vulnerability is fixed in 1.2.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openchoreo openchoreo From 1.2.0-rc.1 (inc) to 1.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OpenChoreo is a developer platform for Kubernetes. This vulnerability allows users with project-scoped permissions to execute commands or view logs in components owned by other projects within the same namespace due to improper authorization checks.

Impact Analysis

An attacker with limited access could escalate privileges to run unauthorized commands or access sensitive logs in other projects, potentially leading to data breaches or system compromise.

Compliance Impact

This vulnerability could violate data protection requirements by allowing unauthorized access to sensitive data, potentially leading to non-compliance with GDPR, HIPAA, or other regulations.

Mitigation Strategies

Upgrade OpenChoreo to version 1.2.0 or later to address the authorization bypass in component:exec and wirelogs:view permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73841. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart