THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qh9r-j7rp-4x2m (critical) — OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

[GHSA] GHSA-qh9r-j7rp-4x2m (critical) — OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

medgithub_advisoriesPublished 2026-09-02

GHSA-qh9r-j7rp-4x2m Severity: critical CVE: CVE-2026-73843

OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

### Summary The OpenChoreo control-plane **cluster-gateway** served its caller-facing management APIs on the same network listener that accepts data-plane agent connections. In the multi-cluster topology that listener is published o

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qh9r-j7rp-4x2m