CVE-2026-44300
published 2026-09-15CVE-2026-44300: OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a…
PriorityP261high8.8CVSS 4.0
AVNACLATNPRNUINVCNVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.75%
53.2th percentile
OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account key.json file returned by GetGCPAuthSecretFilePath in core/pkg/env/core.go. The attacker controls the file contents but not the CONFIG_PATH-derived directory, the key.json filename, or the file mode. Replacing the credential contents can disrupt GCP cost collection or cause OpenCost to use attacker-selected credentials, and the wildcard Access-Control-Allow-Origin response permits browser-assisted requests when the service is reachable from a browser. This issue is fixed in version 1.121.0.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | opencost_opencost | >= 0 < 1.119.1 | 1.119.1 |
| opencost | opencost | < 1.121.0 | 1.121.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenCost up to 1.120.x pkg/costmodel/router.go AddServiceKey input validation (EUVD-2026-78874)
vuldb·2026-09-15·CVSS 8.8
CVE-2026-44300 [HIGH] OpenCost up to 1.120.x pkg/costmodel/router.go AddServiceKey input validation (EUVD-2026-78874)
A vulnerability, which was classified as critical, was found in OpenCost up to 1.120.x. Affected by this vulnerability is the function AddServiceKey of the file pkg/costmodel/router.go. The manipulation results in improper input validation.
This vulnerability was named CVE-2026-44300. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
GHSA
OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection
ghsa·2026-07-14
CVE-2026-44300 [HIGH] CWE-20 OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection
OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection
## Summary
OpenCost contains an unauthenticated file write vulnerability in the `/serviceKey` endpoint that allows remote attackers to overwrite the GCP service account key file without authentication. This can lead to service disruption, credential theft, and potential privilege escalation within Kubernetes clusters.
---
## Affected Versions
- **OpenCost**: All versions up to and including the latest release
- **Vulnerable File**: `pkg/costmodel/router.go` (lines 365-379)
- **Vulnerable Endpoint**: `POST /serviceKey`
---
## Vulnerability Details
### Root Cause
The `AddServiceKey` function in `pkg/costmodel/router.go` accepts user-supplied data via POST request and writes it directly to a file without any au
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/opencost/opencost/commit/69430e7f627b3e62c8999312c06949267fab813ahttps://github.com/opencost/opencost/commit/a49a25bc2e0d6e220a131a4dc58f38ebe6ae851bhttps://github.com/opencost/opencost/pull/3651https://github.com/opencost/opencost/pull/3910https://github.com/opencost/opencost/releases/tag/v1.120.0https://github.com/opencost/opencost/releases/tag/v1.121.0https://github.com/opencost/opencost/security/advisories/GHSA-wmj8-9953-vff5
2026-09-15
Published