CVE-2026-89151

Summary

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

Affected Software

VendorProductVersion RangeStatus
ForgejoForgejo16.0.0 < 16.0.4affected
ForgejoForgejo0 < 15.0.8affected

Weaknesses

  • CWE-863: CWE-863 Incorrect Authorization

References