Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-44300— OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection

Quick assessment

Affected
opencost opencost
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: OpenCost 提供针对 Kubernetes 工作负载和云成本的监控功能。在 1.121.0 版本之前, 中的 端点允许网络客户端在无需强制身份验证的情况下调用 函数,并提交任意键值形式的数据,该数据将被写入由 中 函数返回的 GCP 服务账户 文件。攻击者可以控制文件内容,但无法控制由 派生的目录、 的文件名或文件权限模式。替换凭证内容可能会干扰 GCP 成本收集,或导致 OpenCost 使用攻击者选定的凭证。此外,通配符 响应在浏览器能够访问该服务时,会允许浏览器辅助的请求。

CVSS 8.8 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
opencost opencost < 1.121.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-44300

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection
Source: CVE Program / CVE List V5
Vulnerability Description
OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account key.json file returned by GetGCPAuthSecretFilePath in core/pkg/env/core.go. The attacker controls the file contents but not the CONFIG_PATH-derived directory, the key.json filename, or the file mode. Replacing the credential contents can disrupt GCP cost collection or cause OpenCost to use attacker-selected credentials, and the wildcard Access-Control-Allow-Origin response permits browser-assisted requests when the service is reachable from a browser. This issue is fixed in version 1.121.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
opencost opencost < 1.121.0 -

II. Public POCs for CVE-2026-44300

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-44300

登录查看更多情报信息。

Patches & Fixes for CVE-2026-44300 (4)

Vendor Pages for CVE-2026-44300 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-44300

No comments yet


Leave a comment