CVE-2026-73666
OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth
CVSS
8.2
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 13, 2026 · Last modified: Aug 13, 2026 · CWE-306
Not enough EPSS history yet.
OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated catalog reads, scaffolder log reads, and catalog location creation or deletion. This issue is fixed in versions 1.0.4, 1.1.4, and 1.2.1.
- github.comhttps://github.com/openchoreo/backstage-plugins/commit/114a215689924b917da5fd28c56e679aaccaef07
- github.comhttps://github.com/openchoreo/backstage-plugins/commit/dfa3fc8bd1ffef1346442c891e3e3dd54bc26501
- github.comhttps://github.com/openchoreo/backstage-plugins/commit/f6df89c15834506902b2f706a9e8fbe1f6ef1474
- github.comhttps://github.com/openchoreo/backstage-plugins/commit/fdaceeb737938e830c48a150d5bec24f5f487e52
- github.comhttps://github.com/openchoreo/backstage-plugins/pull/709
- github.comhttps://github.com/openchoreo/backstage-plugins/pull/712
- github.comhttps://github.com/openchoreo/backstage-plugins/pull/713
- github.comhttps://github.com/openchoreo/backstage-plugins/pull/716
- github.comhttps://github.com/openchoreo/backstage-plugins/releases/tag/v1.0.4
- github.comhttps://github.com/openchoreo/backstage-plugins/releases/tag/v1.1.4
- github.comhttps://github.com/openchoreo/backstage-plugins/releases/tag/v1.2.1
- github.comhttps://github.com/openchoreo/openchoreo/security/advisories/GHSA-v7qx-mqhq-grvh
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-736738.8 HIG—
———Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentication because Boa grants access to any path containing '.cgi' regardless of cookie validation, and netis.cgi reads but does not enforce the authentication state before invoking the firmware update handler, which accepts images validated only by a forgeable additive checksum and static product strings rather than a cryptographic signature, potentially enabling persistent router compromise.3hCVE-2026-728229.8 CRI—
———The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads (isSuperAdmin/hasPermission) and never invokes requirePermission(), so the api_key_scopes cap is never applied. As a result, a holder of a narrow-scope API key on a super account, or a non-super account whose ACL includes api.users.write, can force-disable two-factor authentication on any non-super target account via POST /api/v1/users/{user}/2fa/disable without providing a TOTP code, facilitating account takeover.3hCVE-2026-738439.6 CRI—
———OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations, proxy the data-plane Kubernetes API, and execute commands in workload pods in multi-cluster deployments. This issue is fixed in versions 1.0.2 and 1.1.2.21hCVE-2026-738429.0 CRI—
———OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.21hCVE-2026-727769.8 CRI—
———AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands through BashInterpreter using subprocess.Popen with shell=True and safety=False, bypassing the incomplete command blocklist to achieve full host-level code execution.6hCVE-2026-197493.7 LOW—
———A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used.22h