OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated catalog reads, scaffolder log reads, and catalog location creation or deletion. This issue is fixed in versions 1.0.4, 1.1.4, and 1.2.1.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-13 22:17
Updated : 2026-09-08 20:56
NVD link : CVE-2026-73666
Mitre link : CVE-2026-73666
CVE.ORG link : CVE-2026-73666
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
