Description
OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account key.json file returned by GetGCPAuthSecretFilePath in core/pkg/env/core.go. The attacker controls the file contents but not the CONFIG_PATH-derived directory, the key.json filename, or the file mode. Replacing the credential contents can disrupt GCP cost collection or cause OpenCost to use attacker-selected credentials, and the wildcard Access-Control-Allow-Origin response permits browser-assisted requests when the service is reachable from a browser. This issue is fixed in version 1.121.0.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Credential Overwrite/Injection
Action: Immediate Patch
AI Analysis

Impact

OpenCost, a Kubernetes cost‑monitoring solution, exposes an unauthenticated POST /serviceKey endpoint that accepts an arbitrary key form value. The value is written directly to the GCP service‑account key.json file used by OpenCost for authentication. The attacker controls the contents but not the directory path, filename, or file mode. Overwriting the credential file can cause OpenCost to operate with attacker‑selected credentials or lose the ability to collect cost data, potentially leading to data integrity breaches or denial of service. The flaw also reflects insufficient input validation (CWE‑20) and improper handling of credentials (CWE‑309). Moreover, the endpoint’s wildcard Access‑Control‑Allow‑Origin response permits browser‑assisted requests when the service is reachable from a browser.

Affected Systems

The flaw affects OpenCost releases prior to version 1.121.0. Vendors covered are opencost:opencost, whose products include the core cost‑monitoring component deployed within Kubernetes clusters. Only deployments that expose the /serviceKey endpoint via a network route are vulnerable; internal workloads not exposed to external traffic remain protected by default network policies.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity. Its EPSS score is below 1%, suggesting a very low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. An attacker who can reach the exposed endpoint—via a network client or a browser if the service is reachable—can supply a crafted service‑account key. Successful exploitation would allow the attacker to assume the identity of that service account, granting them the same permissions as the account, or to disrupt OpenCost’s cost‑collection process by removing valid credentials.

Generated by OpenCVE AI on September 20, 2026 at 15:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenCost to version 1.121.0 or newer, which removes the unauthenticated endpoint and hardens credential handling.
  • If an upgrade is not immediately feasible, restrict network access to the /serviceKey endpoint using firewall rules or Kubernetes NetworkPolicy to limit it to internal service accounts.
  • Monitor the GCP service‑account key.json file for unexpected changes and enable file‑integrity monitoring or audit logging to detect tampering.

Generated by OpenCVE AI on September 20, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wmj8-9953-vff5 OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection
History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Opencost
Opencost opencost
Vendors & Products Opencost
Opencost opencost

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account key.json file returned by GetGCPAuthSecretFilePath in core/pkg/env/core.go. The attacker controls the file contents but not the CONFIG_PATH-derived directory, the key.json filename, or the file mode. Replacing the credential contents can disrupt GCP cost collection or cause OpenCost to use attacker-selected credentials, and the wildcard Access-Control-Allow-Origin response permits browser-assisted requests when the service is reachable from a browser. This issue is fixed in version 1.121.0.
Title OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection
Weaknesses CWE-20
CWE-309
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Opencost Opencost
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:45:01.536Z

Reserved: 2026-05-05T17:39:31.113Z

Link: CVE-2026-44300

cve-icon Vulnrichment

Updated: 2026-09-15T19:16:36.678Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:21.280

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-44300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:17Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-309

    Use of Password System for Primary Authentication