AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-58416

HIGH · CVSS 7.1 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability exists in the Fork-PR Actions task that allows unauthorized access to a third private repository through the collaborative-owner branch due to a missing fork-PR guard. This could lead to exposure of sensitive data within private repositories. Organizations using Fork-PR Actions for repository management should prioritize addressing this issue to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-58416
Severity
HIGH
CVSS
7.1
EPSS
0.25%

Original NVD Description

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)