Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openchoreo
Openchoreo openchoreo |
|
| Vendors & Products |
Openchoreo
Openchoreo openchoreo |
Thu, 13 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provider from caller-controlled X-Event-Key, accepted Bitbucket requests without HMAC-SHA256 in X-Hub-Signature or a configured bitbucket-secret, and allowed unauthenticated build triggers for components matched by repository URL and branch, including cross-provider triggers using attacker-supplied commit SHAs. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2. | |
| Title | OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) | |
| Weaknesses | CWE-287 CWE-290 CWE-345 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-14T16:26:09.846Z
Reserved: 2026-08-13T17:44:28.640Z
Link: CVE-2026-73840
Updated: 2026-08-14T16:26:02.487Z
Status : Received
Published: 2026-08-13T22:17:28.737
Modified: 2026-08-14T17:20:36.480
Link: CVE-2026-73840
No data.
OpenCVE Enrichment
Updated: 2026-08-14T12:14:32Z