CVE-2026-73840Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provider from caller-controlled X-Event-Key, accepted Bitbucket requests without HMAC-SHA256 in X-Hub-Signature or a configured bitbucket-secret, and allowed unauthenticated build triggers for components matched by repository URL and branch, including cross-provider triggers using attacker-supplied commit SHAs. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-290CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-14); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-14: 1Mentions · 2026-09-03: 1Technical Details · 2026-08-14: 1Technical Details · 2026-09-03: 108-1409-03
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 OpenChoreo, Authentication Bypass, #CVE-2026-73840 (Medium) -DC-Sep2026-2136 https://dailycve.com/openchoreo-authentication-bypass-cve-2026-73840-medium-dc-sep2026-2136/

    Post summary

    The text announces an authentication bypass vulnerability (CVE-2026-73840) in OpenChoreo, rated Medium CVSS, without mentioning any PoC, exploit tool, or active exploitation.

    0000034
    233 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73840 OpenChoreo API Allows Unauthenticated Build Triggers via Webhook https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73840

    Post summary

    The text is a brief disclosure that OpenChoreo’s API allows unauthenticated build triggers via webhooks, but it lacks further technical detail, PoC, or exploitation information.

    00000110
    4.1K followersView on X

Explore more