Vulnerability Description
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in and read wirelogs from components owned by other projects in the same namespace. This vulnerability is fixed in 1.1.6 and 1.2.3.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/openchoreo/openchoreo/commit/4d372eaf1f07525663dcca5257062f4b
- https://github.com/openchoreo/openchoreo/commit/9d77b64f747eba89247c47ebfeffec59
- https://github.com/openchoreo/openchoreo/commit/c9390e4fcb9953f43b07cb4819757618
- https://github.com/openchoreo/openchoreo/pull/4251
- https://github.com/openchoreo/openchoreo/pull/4516
- https://github.com/openchoreo/openchoreo/pull/4538
- https://github.com/openchoreo/openchoreo/releases/tag/v1.1.6
- https://github.com/openchoreo/openchoreo/releases/tag/v1.2.3
- https://github.com/openchoreo/openchoreo/security/advisories/GHSA-52gf-6rpq-fgmx
FAQ
What is CVE-2026-73841?
CVE-2026-73841 is a vulnerability with a CVSS score of 8.8 (HIGH). OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go aut...
How severe is CVE-2026-73841?
CVE-2026-73841 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-73841?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.