{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cluster-gateway--1.0.3-1.1.0-1.1.2-1.2.0-rc.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openchoreo:openchoreo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9,"id":"CVE-2026-73842"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cluster-gateway (\u003c 1.0.3, 1.1.0-1.1.2, 1.2.0-rc.1)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","kubernetes","cloud"],"_cs_type":"advisory","_cs_vendors":["OpenChoreo"],"content_html":"\u003cp\u003eThe OpenChoreo cluster-gateway component suffers from a critical authentication bypass vulnerability (CVE-2026-73842) affecting its internal management APIs, specifically /api/proxy/, /api/exec/, and /api/wirelogs/. These endpoints are designed to tunnel requests to connected Kubernetes data planes but lack any caller authentication or authorization checks. Furthermore, despite being intended for read-only telemetry, the validator allows arbitrary HTTP methods, including those that mutate state or disclose sensitive information. An attacker with network reach to the internal listener can interact with the downstream Kubernetes APIs of any connected data plane as if they were the cluster-gateway itself. This vulnerability creates a significant risk of Secret exfiltration, arbitrary workload modification, and remote code execution via pod exec functionality.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains network reach to the OpenChoreo cluster-gateway internal management port.\u003c/li\u003e\n\u003cli\u003eAttacker probes the internal API endpoints: /api/proxy/, /api/exec/, or /api/wirelogs/.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious request to /api/proxy/ to reach the Kubernetes API server of a connected data plane.\u003c/li\u003e\n\u003cli\u003eAttacker bypasses the non-existent authentication mechanism, as the gateway blindly forwards the request.\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST or PUT request to create or modify Kubernetes resources (e.g., Deployments or Services) in a target namespace.\u003c/li\u003e\n\u003cli\u003eAttacker sends a request to /api/exec/ to execute arbitrary commands inside a target pod, achieving RCE.\u003c/li\u003e\n\u003cli\u003eAttacker reads Kubernetes Secrets in tenant namespaces to harvest database credentials or cloud service keys.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability grants unauthorized full control over connected Kubernetes data planes. Successful exploitation leads to the disclosure of sensitive credentials stored in Kubernetes Secrets, the deployment of malicious workloads, and remote command execution within the tenant environment. This affects all versions of OpenChoreo prior to the specified fixed releases (1.0.3, 1.1.3, 1.2.0), effectively neutralizing data-plane level security controls.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade OpenChoreo immediately to version 1.0.3, 1.1.3, or 1.2.0 to resolve CVE-2026-73842.\u003c/li\u003e\n\u003cli\u003eImplement strict network segmentation to restrict access to the cluster-gateway internal listener.\u003c/li\u003e\n\u003cli\u003eEnsure that internal management ports are not reachable from untrusted workload namespaces using Kubernetes NetworkPolicies.\u003c/li\u003e\n\u003cli\u003eAudit logs for anomalous HTTP POST or PUT requests to /api/proxy/ that target the Kubernetes API server.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-05T00:07:28Z","date_published":"2026-09-05T00:07:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openchoreo-auth-bypass/","summary":"The OpenChoreo cluster-gateway fails to authenticate callers to internal management APIs, allowing unauthorized actors to perform arbitrary Kubernetes API mutations and access Secrets across connected data planes.","title":"OpenChoreo Cluster-Gateway Authentication Bypass and RCE","url":"https://feed.craftedsignal.io/briefs/2026-09-openchoreo-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cluster-Gateway (\u003c 1.0.3, 1.1.0-1.1.2, 1.2.0-Rc.1)","version":"https://jsonfeed.org/version/1.1"}