{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openchoreo-api-v1.2.0-m.1---1.2.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openchoreo:openchoreo_api:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-73841"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["openchoreo-api (v1.2.0-m.1 - 1.2.2)","openchoreo-api (\u003c 1.1.6)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cloud-security","authorization-bypass"],"_cs_type":"advisory","_cs_vendors":["OpenChoreo"],"content_html":"\u003cp\u003eOpenChoreo versions prior to 1.2.3 and 1.1.6 contain an authorization bypass vulnerability (CVE-2026-73841) within the \u003ccode\u003eopenchoreo-api\u003c/code\u003e component's \u003ccode\u003eexec\u003c/code\u003e and \u003ccode\u003ewirelogs\u003c/code\u003e endpoints. The API server incorrectly trusts user-supplied project identifiers to authorize requests instead of validating the target component against its actual owning project recorded in the internal resource hierarchy. Because the authorization engine only verifies if the caller holds a project-scoped grant (such as \u003ccode\u003ecomponent:exec\u003c/code\u003e or \u003ccode\u003ewirelogs:view\u003c/code\u003e), a malicious actor with legitimate access to a single project can perform unauthorized operations on components belonging to other projects within the same Kubernetes namespace. This flaw enables cross-project command execution and unauthorized access to sensitive workload logs, potentially exposing environment variables, credentials, and secrets.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains access to a low-privileged account with a valid \u003ccode\u003ecomponent:exec\u003c/code\u003e or \u003ccode\u003ewirelogs:view\u003c/code\u003e grant for a single project within an OpenChoreo-managed namespace.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a high-value target component in a different project within the same namespace.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request to the \u003ccode\u003eopenchoreo-api\u003c/code\u003e \u003ccode\u003eexec\u003c/code\u003e or \u003ccode\u003ewirelogs\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker substitutes the project parameter in the request with the identifier of the victim's component project.\u003c/li\u003e\n\u003cli\u003eThe API server processes the request, resolving the target component by name without verifying the ownership relationship.\u003c/li\u003e\n\u003cli\u003eThe authorization engine validates the attacker's grant against the caller-supplied (spoofed) project ID.\u003c/li\u003e\n\u003cli\u003eThe server grants the attacker access, permitting command execution or log retrieval from the target component pod.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthorized users to achieve remote command execution or sensitive data exfiltration from workloads they do not own, provided the target is within the same namespace. Successful exploitation allows for the compromise of environment variables and Kubernetes Secrets associated with the targeted component, lateral movement within the cluster, and potential disruption of service integrity across different organizational teams sharing a namespace.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003eopenchoreo-api\u003c/code\u003e to version 1.2.3 or 1.1.6 immediately to enforce correct project-based authorization (CVE-2026-73841).\u003c/li\u003e\n\u003cli\u003eAudit existing \u003ccode\u003ecomponent:exec\u003c/code\u003e and \u003ccode\u003ewirelogs:view\u003c/code\u003e grants to ensure they are restricted to trusted operators only.\u003c/li\u003e\n\u003cli\u003eSegregate highly sensitive components into distinct Kubernetes namespaces to prevent cross-project access while the patch is being deployed.\u003c/li\u003e\n\u003cli\u003eReview cluster-gateway configuration to ensure internal proxies enforce caller authorization, addressing the related security gaps noted in GHSA-rh53-xvx2-j327.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T00:03:08Z","date_published":"2026-09-03T00:03:08Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openchoreo-auth-bypass/","summary":"An authorization flaw in the OpenChoreo API server allows authenticated users with project-scoped grants to execute commands and access logs across different projects within the same namespace.","title":"Authorization Bypass in OpenChoreo API Endpoints","url":"https://feed.craftedsignal.io/briefs/2026-09-openchoreo-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Openchoreo-Api (V1.2.0-M.1 - 1.2.2)","version":"https://jsonfeed.org/version/1.1"}