What is CVE-2026-67349?
OpenCost before version 1.1.121.0 exposes the /helmValues endpoint without authentication, leaking base64-decoded HELM_VALUES environment variable which contains cloud provider credentials. Also, adminAuthMiddleware fails open when ADMIN_TOKEN is not set, meaning unauthenticated attackers can modify GCP service details. Users should urgently update to the patched version.
Azərbaycanca: OpenCost alətinin 1.121.0 versiyasından əvvəlki versiyalarında GET /helmValues endpoint-inin autentifikasiyasızdır, bu da bulud provayderi etimadnamələrini ehtiva edən base64 formatlı HELM_VALUES mühit dəyişənini ifşa edir. Bundan əlavə, ADMIN_TOKEN təyin edilmədikdə adminAuthMiddleware autentifikasiya olmadan keçid verir. Təsirə məruz qalan sistemlərdə dərhal son versiyaya yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of OpenCost are affected by CVE-2026-67349?
All versions of OpenCost before version 1.121.0 are affected by this vulnerability.
What sensitive data does CVE-2026-67349 expose?
This vulnerability exposes the base64-decoded HELM_VALUES environment variable, which contains cloud provider credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.