{"id":"CVE-2026-67349","summary":"OpenCost \u003c 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass","details":"OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is unset, allowing unauthenticated attackers to modify GCP service account keys via POST /serviceKey to redirect billing calls.","modified":"2026-08-02T03:31:57.971536655Z","published":"2026-07-30T14:40:47.996Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67349.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-306"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67349.json"},{"type":"ADVISORY","url":"https://github.com/opencost/opencost/releases/tag/core/v1.121.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67349"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/opencost-unauthenticated-helm-values-exposure-and-admin-bypass"},{"type":"REPORT","url":"https://github.com/opencost/opencost/issues/3893"},{"type":"FIX","url":"https://github.com/opencost/opencost/commit/a49a25bc2e0d6e220a131a4dc58f38ebe6ae851b"},{"type":"FIX","url":"https://github.com/opencost/opencost/pull/3910"},{"type":"PACKAGE","url":"https://github.com/opencost/opencost"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opencost/opencost","events":[{"introduced":"0"},{"fixed":"f5fc438c9a237847964aa561b5a593aa622f91df"},{"fixed":"a49a25bc2e0d6e220a131a4dc58f38ebe6ae851b"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.121.0"}]}}],"versions":["v1.120.4","v1.120","modules/prometheus-source/v1.120.4","modules/collector-source/v1.120.4","core/v1.120.4","v1.120.3","modules/prometheus-source/v1.120.3","modules/collector-source/v1.120.3","core/v1.120.3","v1.120.2","modules/prometheus-source/v1.120.2","modules/collector-source/v1.120.2","core/v1.120.2","kc-3.2.1-rc.4","kc-3.2.1-rc.2","kc-3.2.1","kc-3.2.0-rc.3","kc-3.2.0-rc.2","kc-3.2.0-rc.1","kc-3.2.0-rc.0","kc-3.2.0","v1.120.1","modules/prometheus-source/v1.120.1","modules/collector-source/v1.120.1","core/v1.120.1","v1.120.0","modules/prometheus-source/v1.120.0","modules/collector-source/v1.120.0","core/v1.120.0","v1.119.2","v1.119","modules/prometheus-source/v1.119.2","modules/collector-source/v1.119.2","core/v1.119.2","v1.119.1","modules/prometheus-source/v1.119.1","modules/collector-source/v1.119.1","kc-3.1.0-rc.0","kc-3.1.0","core/v1.119.1","v1.119.0","modules/prometheus-source/v1.119.0","modules/collector-source/v1.119.0","core/v1.119.0","v1.118.1","modules/prometheus-source/v1.118.1","modules/collector-source/v1.118.1","core/v1.118.1","v1.118.0","v1.118","modules/prometheus-source/v1.118.0","modules/collector-source/v1.118.0","kc-3.0.4-rc.0","kc-3.0.3-rc.1","kc-3.0.3-rc.0","kc-3.0.3","core/v1.118.0","kc-2.9.7","v1.117.5","modules/prometheus-source/v1.117.5","modules/collector-source/v1.117.5","kc-3.0.0-rc.6","kc-3.0.0-rc.5","kc-3.0.0","core/v1.117.5","v1.117.6","v1.117","modules/prometheus-source/v1.117.6","modules/collector-source/v1.117.6","core/v1.117.6","v1.117.4","kc-3.0.0-rc.2","kc-3.0.0-rc.1","kc-3.0.0-rc.0","v1.117.2","modules/prometheus-source/v1.117.2","modules/collector-source/v1.117.2","kc-3.0.0-test.0","core/v1.117.2","v1.117.3","modules/prometheus-source/v1.117.3","modules/collector-source/v1.117.3","core/v1.117.3","v1.117.0","modules/prometheus-source/v1.117.0","modules/collector-source/v1.117.0","core/v1.117.0","v1.116.0","v1.116","kc-2.8.0-rc.0","kc-2.7.0-rc.2","kc-2.7.0-rc.1","kc-2.7.0-rc.0","kc-2.7.0","v2.6.0-rc.0","kc-2.6.5-rc.1","kc-2.6.5-rc.0","kc-2.6.5","kc-2.6.4-rc.0","kc-2.6.4","kc-2.6.3-rc.2","kc-2.6.3","kc-2.6.2-rc.1","kc-2.6.2-rc.0","kc-2.6.2","kc-2.6.1-rc.2","kc-2.6.1-rc.1","kc-2.6.1-rc.0","kc-2.6.1","kc-2.6.0-rc.7","kc-2.6.0-rc.6","kc-2.6.0-rc.5","kc-2.6.0-rc.4","kc-2.6.0-rc.3","kc-2.6.0-rc.2","kc-2.6.0-rc.1","kc-2.6.0","kc-2.5.5-rc.2","kc-2.5.5-rc.1","kc-2.5.5-rc.0","kc-2.5.5","kc-2.5.4-rc.4","kc-2.5.4-rc.3","kc-2.5.4","v1.114.0","v2.5.0-rc.1","v2.5.0-rc.0","v1.113.0","v1.112.0","v2.4.0-rc.0","v1.111.0","v1.110","v2.3.0-rc.0","v2.2.0-rc.2","v2.2.0-rc.1","v2.2.0-rc.0","v2.1.0-rc.5","v2.1.0-rc.4","v2.1.0-rc.3","v2.1.0-rc.2","v2.1.0-rc.1","v2.1.0-rc.0","v1.109","v2.0.0-rc.1","v2.0.0-rc.0","v1.107.0-rc.0","v0.0.1-depotprodtestrun.1","v0.0.1-actdev.2","v1.106.0-rc.1","v1.106.0-rc.0","v1.105.0-rc.0","v0.0.1-depotdev.01","v0.0.1-actdev.1","v0.0.0000001-depotdev.01","v0.0.000000001-rc.0","v0.0.0000000001-test.0","v0.0.0000000001-rc.0","v1.104.0-rc.0","v1.103.0-rc.1","v1.103.0-rc.0","v1.102.0-rc.0","v0.000000001.0-rc.0","v1.91.0-rc.0","v1.45.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67349.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}