High severity8.8NVD Advisory· Published Aug 13, 2026· Updated Sep 8, 2026
CVE-2026-73841
CVE-2026-73841
Description
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in and read wirelogs from components owned by other projects in the same namespace. This vulnerability is fixed in 1.1.6 and 1.2.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/openchoreo/openchoreoGo | >= 1.2.0-m.1, < 1.2.3 | 1.2.3 |
github.com/openchoreo/openchoreoGo | < 1.1.6 | 1.1.6 |
Affected products
1- Range: <1.1.6, <1.2.3
Patches
Vulnerability mechanics
References
11- github.com/advisories/GHSA-52gf-6rpq-fgmxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-73841ghsaADVISORY
- github.com/openchoreo/openchoreo/commit/4d372eaf1f07525663dcca5257062f4b051b9820nvdWEB
- github.com/openchoreo/openchoreo/commit/9d77b64f747eba89247c47ebfeffec591c4cd2d8nvdWEB
- github.com/openchoreo/openchoreo/commit/c9390e4fcb9953f43b07cb48197576182301593dnvdWEB
- github.com/openchoreo/openchoreo/pull/4251nvdWEB
- github.com/openchoreo/openchoreo/pull/4516nvdWEB
- github.com/openchoreo/openchoreo/pull/4538nvdWEB
- github.com/openchoreo/openchoreo/releases/tag/v1.1.6nvdWEB
- github.com/openchoreo/openchoreo/releases/tag/v1.2.3nvdWEB
- github.com/openchoreo/openchoreo/security/advisories/GHSA-52gf-6rpq-fgmxnvdWEB
News mentions
0No linked articles in our index yet.