{"id":"CVE-2026-73841","summary":"OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints","details":"OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in and read wirelogs from components owned by other projects in the same namespace. This vulnerability is fixed in 1.1.6 and 1.2.3.","aliases":["GHSA-52gf-6rpq-fgmx","GO-2026-6358"],"modified":"2026-09-10T15:25:27.982893607Z","published":"2026-08-13T21:56:13.057Z","database_specific":{"cwe_ids":["CWE-639","CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73841.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/openchoreo/openchoreo/releases/tag/v1.1.6"},{"type":"WEB","url":"https://github.com/openchoreo/openchoreo/releases/tag/v1.2.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73841.json"},{"type":"ADVISORY","url":"https://github.com/openchoreo/openchoreo/security/advisories/GHSA-52gf-6rpq-fgmx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73841"},{"type":"FIX","url":"https://github.com/openchoreo/openchoreo/commit/4d372eaf1f07525663dcca5257062f4b051b9820"},{"type":"FIX","url":"https://github.com/openchoreo/openchoreo/commit/9d77b64f747eba89247c47ebfeffec591c4cd2d8"},{"type":"FIX","url":"https://github.com/openchoreo/openchoreo/commit/c9390e4fcb9953f43b07cb48197576182301593d"},{"type":"FIX","url":"https://github.com/openchoreo/openchoreo/pull/4251"},{"type":"FIX","url":"https://github.com/openchoreo/openchoreo/pull/4516"},{"type":"FIX","url":"https://github.com/openchoreo/openchoreo/pull/4538"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openchoreo/openchoreo","events":[{"introduced":"83a9edc709511fbd0e0f3458aaece4d0d9d0d3fe"},{"introduced":"0"},{"fixed":"446ff682e2a662b13bc0bfbdfa475f7858b50ab7"},{"fixed":"13992ba9cf2ee559407228e3b626ef9b99383ce8"},{"fixed":"4d372eaf1f07525663dcca5257062f4b051b9820"},{"fixed":"9d77b64f747eba89247c47ebfeffec591c4cd2d8"},{"fixed":"c9390e4fcb9953f43b07cb48197576182301593d"}],"database_specific":{"extracted_events":[{"introduced":"1.2.0-m.1"},{"fixed":"1.2.3"},{"introduced":"0"},{"fixed":"1.1.6"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.1.5","v1.2.2","v1.2.1","v1.1.4","v1.2.0","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.0","v1.0.0-rc.2","v1.0.0-rc.1","v0.17.0","v0.16.0","v0.14.0","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.8.0","v0.7.0","v0.6.0","v0.4.0","v0.5.0","v0.3.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73841.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}