CVE-2026-73841High· 8.8▾ TwilightOpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:vi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
0.4% → 0.5%
Last analysed / modified upstream
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in and read wirelogs from components owned by other projects in the same namespace. This vulnerability is fixed in 1.1.6 and 1.2.3.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/openchoreo/openchoreo >= 1.2.0-m.1, < 1.2.3github.com/openchoreo/openchoreo < 1.1.6Patched in:
github.com/openchoreo/openchoreo 1.2.3github.com/openchoreo/openchoreo 1.1.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73667High· 8.8OpenChoreo is a complete, open-source developer platform for Kubernetes
CVE-2026-73842Critical· 9.0OpenChoreo is a complete, open-source developer platform for Kubernetes
CVE-2026-73843Critical· 9.6OpenChoreo is a complete, open-source developer platform for Kubernetes
CVE-2026-73840Medium· 5.3OpenChoreo is a complete, open-source developer platform for Kubernetes
CVE-2026-53552Critical· 9.6Goploy is an open-source automation deployment system
CVE-2026-47101High· 8.8LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit