๐Ÿ” CVE Alert

CVE-2026-44300

UNKNOWN 0.0

OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account key.json file returned by GetGCPAuthSecretFilePath in core/pkg/env/core.go. The attacker controls the file contents but not the CONFIG_PATH-derived directory, the key.json filename, or the file mode. Replacing the credential contents can disrupt GCP cost collection or cause OpenCost to use attacker-selected credentials, and the wildcard Access-Control-Allow-Origin response permits browser-assisted requests when the service is reachable from a browser. This issue is fixed in version 1.121.0.

CWE CWE-20 CWE-309
Vendor opencost
Product opencost
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for opencost opencost

Be the first to know when new unknown vulnerabilities affecting opencost opencost are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

opencost / opencost
< 1.121.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/opencost/opencost/security/advisories/GHSA-wmj8-9953-vff5 github.com: https://github.com/opencost/opencost/pull/3651 github.com: https://github.com/opencost/opencost/pull/3910 github.com: https://github.com/opencost/opencost/commit/69430e7f627b3e62c8999312c06949267fab813a github.com: https://github.com/opencost/opencost/commit/a49a25bc2e0d6e220a131a4dc58f38ebe6ae851b github.com: https://github.com/opencost/opencost/releases/tag/v1.120.0 github.com: https://github.com/opencost/opencost/releases/tag/v1.121.0