Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opencost
Opencost opencost |
|
| Vendors & Products |
Opencost
Opencost opencost |
Thu, 30 Jul 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is unset, allowing unauthenticated attackers to modify GCP service account keys via POST /serviceKey to redirect billing calls. | |
| Title | OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-30T14:40:47.996Z
Reserved: 2026-07-29T13:36:36.277Z
Link: CVE-2026-67349
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T20:26:28Z
-
CWE-306
Missing Authentication for Critical Function