OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is unset, allowing unauthenticated attackers to modify GCP service account keys via POST /serviceKey to redirect billing calls.
References
Configurations
No configuration.
History
30 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-30 15:16
Updated : 2026-07-31 23:17
NVD link : CVE-2026-67349
Mitre link : CVE-2026-67349
CVE.ORG link : CVE-2026-67349
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
