{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/opencost/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-67349"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenCost"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenCost"],"content_html":"\u003cp\u003eOpenCost versions prior to 1.121.0 are vulnerable to multiple authentication bypass flaws that facilitate credential access and administrative manipulation. The vulnerability stems from two primary failures in the application's authentication logic. First, the GET /helmValues endpoint does not perform authentication, which exposes the base64-encoded HELM_VALUES environment variable to unauthenticated attackers. This variable typically contains sensitive cloud provider credentials, such as API keys or service account details.\u003c/p\u003e\n\u003cp\u003eSecond, the adminAuthMiddleware fails to enforce authentication requirements when the ADMIN_TOKEN environment variable is not set. This allows unauthenticated actors to interact with restricted administrative endpoints, specifically enabling the unauthorized modification of GCP service account keys via the POST /serviceKey endpoint. This could allow an attacker to redirect billing calls or escalate privileges within the compromised cloud environment. Defenders must prioritize upgrading to version 1.121.0 or ensuring that the ADMIN_TOKEN is strictly configured in all production deployments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing or internally accessible OpenCost endpoints.\u003c/li\u003e\n\u003cli\u003eAttacker sends an unauthenticated GET request to the /helmValues endpoint.\u003c/li\u003e\n\u003cli\u003eThe OpenCost server returns the contents of the HELM_VALUES environment variable, including sensitive cloud provider credentials.\u003c/li\u003e\n\u003cli\u003eAttacker decodes the base64-encoded response to retrieve the plain-text credentials.\u003c/li\u003e\n\u003cli\u003eAttacker attempts an unauthenticated POST request to the /serviceKey endpoint.\u003c/li\u003e\n\u003cli\u003eThe server confirms the adminAuthMiddleware is inactive due to the absence of the ADMIN_TOKEN.\u003c/li\u003e\n\u003cli\u003eAttacker successfully submits a modified GCP service account key to the endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker achieves the final objective of redirecting billing calls or maintaining persistence within the GCP environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability exposes sensitive cloud provider credentials to unauthenticated attackers, potentially leading to unauthorized access to cloud resources. Successful exploitation of the service key modification allows attackers to redirect billing traffic, resulting in financial loss and potential data exfiltration paths through GCP service accounts. This issue affects any organization deploying OpenCost versions older than 1.121.0 without explicit ADMIN_TOKEN enforcement.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all OpenCost deployments to version 1.121.0 or newer.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, enforce a strong, non-default ADMIN_TOKEN across all OpenCost instances to prevent the adminAuthMiddleware from failing open.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect unauthenticated attempts to access sensitive endpoints.\u003c/li\u003e\n\u003cli\u003eAudit cloud service account logs (GCP) for any suspicious modifications to service key objects, correlating these with source IP addresses associated with OpenCost instances.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-30T15:33:54Z","date_published":"2026-07-30T15:33:54Z","id":"https://feed.craftedsignal.io/briefs/2026-07-opencost-auth-bypass/","summary":"OpenCost versions before 1.121.0 contain authentication bypass vulnerabilities allowing unauthenticated credential exfiltration via GET /helmValues and unauthorized service key modification via POST /serviceKey.","title":"Authentication Bypass and Credential Exposure in OpenCost","url":"https://feed.craftedsignal.io/briefs/2026-07-opencost-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenCost","version":"https://jsonfeed.org/version/1.1"}