A vulnerability was found in OpenChoreo up to 1.0.2/1.1.2 . It has been declared as critical . The affected element is an unknown function of the file internal/openchoreo-api/api/handlers/webhook_handler.go of the component Webhook Handler . The manipulation of the argument X-Event-Key results in improper authentication. This vulnerability is cataloged as CVE-2026-73840 . The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.