CVE-2026-92764: Opencve
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to, bypassing intended token isolation boundaries.
Affected products
- Opencve Opencve: from 2.4.0, before 3.1.0 (fixed in 3.1.0)
Published 2026-09-16. Last modified 2026-09-23.