{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "1.0.4"
              },
              {
                "introduced": "1.1.0"
              },
              {
                "fixed": "1.1.4"
              },
              {
                "introduced": "1.2.0-rc.1"
              },
              {
                "fixed": "1.2.1"
              }
            ],
            "source": [
              "AFFECTED_FIELD",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "introduced": "0346616c3a41175fe5647a3da7462b7b659a4d5f"
            },
            {
              "introduced": "33abf75137b4662051259596b12ceb51ed20f506"
            },
            {
              "fixed": "f61957e261df28352e083f50c4cb2a3be1f0dba5"
            },
            {
              "fixed": "b0a4247b097388c967d4d1473e495e3fa314eaaa"
            },
            {
              "fixed": "294f19462f41d9e4f2fd71b7c64eef5977136da1"
            },
            {
              "fixed": "114a215689924b917da5fd28c56e679aaccaef07"
            },
            {
              "fixed": "dfa3fc8bd1ffef1346442c891e3e3dd54bc26501"
            },
            {
              "fixed": "f6df89c15834506902b2f706a9e8fbe1f6ef1474"
            },
            {
              "fixed": "fdaceeb737938e830c48a150d5bec24f5f487e52"
            }
          ],
          "repo": "https://github.com/openchoreo/backstage-plugins",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-v7qx-mqhq-grvh"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73666.json"
  },
  "details": "OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated catalog reads, scaffolder log reads, and catalog location creation or deletion. This issue is fixed in versions 1.0.4, 1.1.4, and 1.2.1.",
  "id": "CVE-2026-73666",
  "modified": "2026-08-16T03:31:24.144172983Z",
  "published": "2026-08-13T21:40:13.597Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/openchoreo/backstage-plugins/releases/tag/v1.0.4"
    },
    {
      "type": "WEB",
      "url": "https://github.com/openchoreo/backstage-plugins/releases/tag/v1.1.4"
    },
    {
      "type": "WEB",
      "url": "https://github.com/openchoreo/backstage-plugins/releases/tag/v1.2.1"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73666.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/openchoreo/openchoreo/security/advisories/GHSA-v7qx-mqhq-grvh"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73666"
    },
    {
      "type": "FIX",
      "url": "https://github.com/openchoreo/backstage-plugins/commit/114a215689924b917da5fd28c56e679aaccaef07"
    },
    {
      "type": "FIX",
      "url": "https://github.com/openchoreo/backstage-plugins/commit/dfa3fc8bd1ffef1346442c891e3e3dd54bc26501"
    },
    {
      "type": "FIX",
      "url": "https://github.com/openchoreo/backstage-plugins/commit/f6df89c15834506902b2f706a9e8fbe1f6ef1474"
    },
    {
      "type": "FIX",
      "url": "https://github.com/openchoreo/backstage-plugins/commit/fdaceeb737938e830c48a150d5bec24f5f487e52"
    },
    {
      "type": "FIX",
      "url": "https://github.com/openchoreo/backstage-plugins/pull/709"
    },
    {
      "type": "FIX",
      "url": "https://github.com/openchoreo/backstage-plugins/pull/712"
    },
    {
      "type": "FIX",
      "url": "https://github.com/openchoreo/backstage-plugins/pull/713"
    },
    {
      "type": "FIX",
      "url": "https://github.com/openchoreo/backstage-plugins/pull/716"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/delete"
}