Openchoreo

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 6
    Known Exploited: 0
    2
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-73843

    OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

    Last Modified: Aug 14, 2026
    Published: Aug 13, 2026

    CVE-2026-73842

    OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

    Last Modified: Aug 18, 2026
    Published: Aug 13, 2026

    CVE-2026-73841

    OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints

    Last Modified: Sep 02, 2026
    Published: Aug 13, 2026

    CVE-2026-73840

    OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)

    Last Modified: Aug 14, 2026
    Published: Aug 13, 2026

    CVE-2026-73667

    OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods

    Last Modified: Aug 17, 2026
    Published: Aug 13, 2026
    Items Per Page
    Openchoreo Vulnerabilities & Security CVEs | CVE-DB