CVE-2026-92764 UNKNOWN

CVE-2026-92764

Published: 2026-09-16

Description

OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to, bypassing intended token isolation boundaries.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…