Vulnerability Description
OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated catalog reads, scaffolder log reads, and catalog location creation or deletion. This issue is fixed in versions 1.0.4, 1.1.4, and 1.2.1.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/openchoreo/backstage-plugins/commit/114a215689924b917da5fd28c
- https://github.com/openchoreo/backstage-plugins/commit/dfa3fc8bd1ffef1346442c891
- https://github.com/openchoreo/backstage-plugins/commit/f6df89c15834506902b2f706a
- https://github.com/openchoreo/backstage-plugins/commit/fdaceeb737938e830c48a150d
- https://github.com/openchoreo/backstage-plugins/pull/709
- https://github.com/openchoreo/backstage-plugins/pull/712
- https://github.com/openchoreo/backstage-plugins/pull/713
- https://github.com/openchoreo/backstage-plugins/pull/716
- https://github.com/openchoreo/backstage-plugins/releases/tag/v1.0.4
- https://github.com/openchoreo/backstage-plugins/releases/tag/v1.1.4
- https://github.com/openchoreo/backstage-plugins/releases/tag/v1.2.1
- https://github.com/openchoreo/openchoreo/security/advisories/GHSA-v7qx-mqhq-grvh
FAQ
What is CVE-2026-73666?
CVE-2026-73666 is a vulnerability with a CVSS score of 8.2 (HIGH). OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.gues...
How severe is CVE-2026-73666?
CVE-2026-73666 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-73666?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.