API Token Misconfiguration in OpenCVE by OpenCVE
CVE-2026-92764

5.3MEDIUM

Key Information:

Vendor

Opencve

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92764?

OpenCVE versions prior to 3.1.0 contain a vulnerability affecting the organization API endpoint, which does not correctly restrict access based on the token's associated organization. As a result, an attacker with organization-scoped tokens can query and retrieve memberships from multiple organizations that the token creator is part of, undermining the intended isolation measures put in place. This design flaw can lead to unauthorized access to sensitive organization data, making it critical for users to upgrade to version 3.1.0 or later to mitigate this risk.

Affected Version(s)

opencve 0 < 3.1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.