CVE-2026-67349
HIGHOpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass
Title source: cnaDescription
OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is unset, allowing unauthenticated attackers to modify GCP service account keys via POST /serviceKey to redirect billing calls.
References (5)
Core 5
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/opencost/opencost/issues/3893
Release Notes release-notes
Release Notes
https://github.com/opencost/opencost/releases/tag/core/v1.121.0
Patch patch
Patch Commit
https://github.com/opencost/opencost/commit/a49a25bc2e0d6e220a131a4dc58f38ebe6ae851b
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/opencost-unauthenticated-helm-values-exposure-and-admin-bypass
Scores
CVSS v3
7.5
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-306
Status
published
Products (1)
opencost/opencost
< 1.121.0
Published
Jul 30, 2026
Tracked Since
Jul 30, 2026