OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated catalog reads, scaffolder log reads, and catalog location creation or deletion. This issue is fixed in versions 1.0.4, 1.1.4, and 1.2.1.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openchoreo
Openchoreo backstage-plugins |
|
| Vendors & Products |
Openchoreo
Openchoreo backstage-plugins |
Thu, 13 Aug 2026 22:00:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-13T22:03:27.006Z
Reserved: 2026-08-13T14:04:09.606Z
Link: CVE-2026-73666
No data.
Status : Received
Published: 2026-08-13T22:17:28.393
Modified: 2026-08-13T22:17:28.393
Link: CVE-2026-73666
No data.
OpenCVE Enrichment
Updated: 2026-08-14T09:30:17Z
Weaknesses