SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-89151

LOW · CVSS 3.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Forgejo versions prior to 16.0.4 are vulnerable to unauthorized access through restricted API tokens, specifically affecting the "allow maintainer edit" feature. This could potentially allow users to perform actions they should not be permitted to, posing a risk to repository integrity. Organizations using affected versions should prioritize updating to mitigate this low-severity vulnerability.

CVE
CVE-2026-89151
Severity
LOW
CVSS
3.5
EPSS
0.15%

Original NVD Description

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.