CVE-2026-89151
3.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Summary
Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Forgejo | Forgejo | 16.0.0 < 16.0.4 | affected |
| Forgejo | Forgejo | 0 < 15.0.8 | affected |
Weaknesses
- CWE-863: CWE-863 Incorrect Authorization
References
- https://codeberg.org/forgejo/forgejo/milestone/139655
- https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/15.0.8.md
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.