{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openchoreo-cluster-gateway--1.0.2--1.1.0--1.1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openchoreo:openchoreo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-73843"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenChoreo cluster-gateway (\u003c 1.0.2, \u003e= 1.1.0, \u003c 1.1.2)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenChoreo"],"content_html":"\u003cp\u003eOpenChoreo (CVE-2026-73843) contains a critical authentication flaw in its cluster-gateway component. In multi-cluster topologies, the cluster-gateway provides an externally published endpoint to facilitate connectivity for remote data-plane agents. It was discovered that the management APIs intended for internal use were erroneously hosted on this same externally accessible network listener. Because these management APIs lacked authentication or authorization checks, any party with network reachability to the cluster-gateway endpoint can interact with privileged data-plane operations. This exposes the ability to proxy the data plane's underlying Kubernetes API and execute arbitrary commands within workload pods. The vulnerability affects versions of the OpenChoreo cluster-gateway below 1.0.2, those between 1.1.0 and 1.1.1, and the 1.2.0 release line. The vulnerability is mitigated by moving management APIs to a non-public internal listener, restricting access to the external-facing gateway to agent-connection traffic only.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify exposed OpenChoreo cluster-gateway endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker confirms the target is a multi-cluster deployment with an externally published listener.\u003c/li\u003e\n\u003cli\u003eAttacker sends unauthenticated HTTP requests to the identified management API paths on the gateway listener.\u003c/li\u003e\n\u003cli\u003eAttacker invokes privileged API operations intended for the OpenChoreo control-plane.\u003c/li\u003e\n\u003cli\u003eAttacker proxies requests to the underlying data-plane Kubernetes API.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the proxied API access to target specific workload pods.\u003c/li\u003e\n\u003cli\u003eAttacker executes arbitrary commands or manipulates workloads, leading to full compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to a complete compromise of the data-plane workloads. This includes unauthorized data disclosure, unauthorized modification of services, and potential denial of service. The impact is significant for organizations relying on OpenChoreo for multi-cluster management, as the vulnerability bypasses existing control-plane authorization, granting an unauthenticated attacker the same privileges as an authenticated internal client.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for addressing CVE-2026-73843:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade OpenChoreo cluster-gateway to versions 1.0.2, 1.1.2, or 1.2.0 immediately to move management APIs to a secure internal listener.\u003c/li\u003e\n\u003cli\u003eFor deployments that cannot be patched immediately, apply firewall or network policy rules to restrict the externally published gateway endpoint to only allow traffic from authorized data-plane source addresses.\u003c/li\u003e\n\u003cli\u003eReview ingress and network telemetry to identify unauthorized access attempts to the management API paths on the cluster-gateway listener.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T00:02:42Z","date_published":"2026-09-03T00:02:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openchoreo-unauth-access/","summary":"OpenChoreo cluster-gateway versions prior to 1.0.2, 1.1.2, and 1.2.0 are vulnerable to unauthenticated access of management APIs on externally exposed listeners, enabling remote execution and cluster-wide compromise.","title":"Unauthenticated API Access in OpenChoreo Cluster-Gateway","url":"https://feed.craftedsignal.io/briefs/2026-09-openchoreo-unauth-access/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenChoreo Cluster-Gateway (\u003c 1.0.2, \u003e= 1.1.0, \u003c 1.1.2)","version":"https://jsonfeed.org/version/1.1"}