Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

OpenChoreo unauthenticated cluster-gateway management API access

OpenChoreo's cluster-gateway served unauthenticated management APIs on the same listener accepting data-plane connections, allowing attackers reaching the external endpoint to perform privileged operations including Kubernetes API proxy and pod command execution without authentication.

Disclosed 2 September 2026 · Record updated 13 September 2026

Impact

Attackers with network access to the externally published cluster-gateway endpoint can perform unrestricted data-plane operations, potentially achieving full compromise of workloads including disclosure, tampering, and denial of service.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-qh9r-j7rp-4x2m