API Token Misconfiguration in OpenCVE by OpenCVE
CVE-2026-92764
5.3MEDIUM
What is CVE-2026-92764?
OpenCVE versions prior to 3.1.0 contain a vulnerability affecting the organization API endpoint, which does not correctly restrict access based on the token's associated organization. As a result, an attacker with organization-scoped tokens can query and retrieve memberships from multiple organizations that the token creator is part of, undermining the intended isolation measures put in place. This design flaw can lead to unauthorized access to sensitive organization data, making it critical for users to upgrade to version 3.1.0 or later to mitigate this risk.
Affected Version(s)
opencve 0 < 3.1.0
