{"id":"CVE-2026-44300","summary":"OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection","details":"OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account key.json file returned by GetGCPAuthSecretFilePath in core/pkg/env/core.go. The attacker controls the file contents but not the CONFIG_PATH-derived directory, the key.json filename, or the file mode. Replacing the credential contents can disrupt GCP cost collection or cause OpenCost to use attacker-selected credentials, and the wildcard Access-Control-Allow-Origin response permits browser-assisted requests when the service is reachable from a browser. This issue is fixed in version 1.121.0.","aliases":["GHSA-wmj8-9953-vff5","GO-2026-5974"],"modified":"2026-09-17T03:45:57.330051901Z","published":"2026-09-15T17:08:15.845Z","related":["openSUSE-SU-2026:21483-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44300.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-20","CWE-309"]},"references":[{"type":"WEB","url":"https://github.com/opencost/opencost/releases/tag/v1.120.0"},{"type":"WEB","url":"https://github.com/opencost/opencost/releases/tag/v1.121.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44300.json"},{"type":"ADVISORY","url":"https://github.com/opencost/opencost/security/advisories/GHSA-wmj8-9953-vff5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44300"},{"type":"FIX","url":"https://github.com/opencost/opencost/commit/69430e7f627b3e62c8999312c06949267fab813a"},{"type":"FIX","url":"https://github.com/opencost/opencost/commit/a49a25bc2e0d6e220a131a4dc58f38ebe6ae851b"},{"type":"FIX","url":"https://github.com/opencost/opencost/pull/3651"},{"type":"FIX","url":"https://github.com/opencost/opencost/pull/3910"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opencost/opencost","events":[{"introduced":"0"},{"fixed":"69430e7f627b3e62c8999312c06949267fab813a"},{"fixed":"a49a25bc2e0d6e220a131a4dc58f38ebe6ae851b"},{"fixed":"22da667c047765788a5cb8b01c1e8ad4cb87fc0a"},{"fixed":"f5fc438c9a237847964aa561b5a593aa622f91df"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.121.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.120.4","v1.120","modules/prometheus-source/v1.120.4","modules/collector-source/v1.120.4","core/v1.120.4","v1.120.3","modules/prometheus-source/v1.120.3","modules/collector-source/v1.120.3","core/v1.120.3","v1.120.2","modules/prometheus-source/v1.120.2","modules/collector-source/v1.120.2","core/v1.120.2","kc-3.2.1-rc.4","kc-3.2.1-rc.2","kc-3.2.1","kc-3.2.0-rc.3","kc-3.2.0-rc.2","kc-3.2.0-rc.1","kc-3.2.0-rc.0","kc-3.2.0","v1.120.1","modules/prometheus-source/v1.120.1","modules/collector-source/v1.120.1","core/v1.120.1","v1.120.0","modules/prometheus-source/v1.120.0","modules/collector-source/v1.120.0","core/v1.120.0","v1.119.2","v1.119","modules/prometheus-source/v1.119.2","modules/collector-source/v1.119.2","core/v1.119.2","v1.119.1","modules/prometheus-source/v1.119.1","modules/collector-source/v1.119.1","kc-3.1.0-rc.0","kc-3.1.0","core/v1.119.1","v1.119.0","modules/prometheus-source/v1.119.0","modules/collector-source/v1.119.0","core/v1.119.0","v1.118.1","modules/prometheus-source/v1.118.1","modules/collector-source/v1.118.1","core/v1.118.1","v1.118.0","v1.118","modules/prometheus-source/v1.118.0","modules/collector-source/v1.118.0","kc-3.0.4-rc.0","kc-3.0.3-rc.1","kc-3.0.3-rc.0","kc-3.0.3","core/v1.118.0","kc-2.9.7","v1.117.5","modules/prometheus-source/v1.117.5","modules/collector-source/v1.117.5","kc-3.0.0-rc.6","kc-3.0.0-rc.5","kc-3.0.0","core/v1.117.5","v1.117.6","v1.117","modules/prometheus-source/v1.117.6","modules/collector-source/v1.117.6","core/v1.117.6","v1.117.4","kc-3.0.0-rc.2","kc-3.0.0-rc.1","kc-3.0.0-rc.0","v1.117.2","modules/prometheus-source/v1.117.2","modules/collector-source/v1.117.2","kc-3.0.0-test.0","core/v1.117.2","v1.117.3","modules/prometheus-source/v1.117.3","modules/collector-source/v1.117.3","core/v1.117.3","v1.117.0","modules/prometheus-source/v1.117.0","modules/collector-source/v1.117.0","core/v1.117.0","v1.116.0","v1.116","kc-2.8.0-rc.0","kc-2.7.0-rc.2","kc-2.7.0-rc.1","kc-2.7.0-rc.0","kc-2.7.0","v2.6.0-rc.0","kc-2.6.5-rc.1","kc-2.6.5-rc.0","kc-2.6.5","kc-2.6.4-rc.0","kc-2.6.4","kc-2.6.3-rc.2","kc-2.6.3","kc-2.6.2-rc.1","kc-2.6.2-rc.0","kc-2.6.2","kc-2.6.1-rc.2","kc-2.6.1-rc.1","kc-2.6.1-rc.0","kc-2.6.1","kc-2.6.0-rc.7","kc-2.6.0-rc.6","kc-2.6.0-rc.5","kc-2.6.0-rc.4","kc-2.6.0-rc.3","kc-2.6.0-rc.2","kc-2.6.0-rc.1","kc-2.6.0","kc-2.5.5-rc.2","kc-2.5.5-rc.1","kc-2.5.5-rc.0","kc-2.5.5","kc-2.5.4-rc.4","kc-2.5.4-rc.3","kc-2.5.4","v1.114.0","v2.5.0-rc.1","v2.5.0-rc.0","v1.113.0","v1.112.0","v2.4.0-rc.0","v1.111.0","v1.110","v2.3.0-rc.0","v2.2.0-rc.2","v2.2.0-rc.1","v2.2.0-rc.0","v2.1.0-rc.5","v2.1.0-rc.4","v2.1.0-rc.3","v2.1.0-rc.2","v2.1.0-rc.1","v2.1.0-rc.0","v1.109","v2.0.0-rc.1","v2.0.0-rc.0","v1.107.0-rc.0","v0.0.1-depotprodtestrun.1","v0.0.1-actdev.2","v1.106.0-rc.1","v1.106.0-rc.0","v1.105.0-rc.0","v0.0.1-depotdev.01","v0.0.1-actdev.1","v0.0.0000001-depotdev.01","v0.0.000000001-rc.0","v0.0.0000000001-test.0","v0.0.0000000001-rc.0","v1.104.0-rc.0","v1.103.0-rc.1","v1.103.0-rc.0","v1.102.0-rc.0","v0.000000001.0-rc.0","v1.91.0-rc.0","v1.45.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44300.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"}]}