Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature. | |
| First Time appeared |
Forgejo
Forgejo forgejo |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:forgejo:forgejo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Forgejo
Forgejo forgejo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-09-11T02:23:27.866Z
Updated: 2026-09-11T02:23:27.866Z
Reserved: 2026-09-11T02:23:27.533Z
Link: CVE-2026-89151
No data.
Status : Received
Published: 2026-09-11T03:16:24.450
Modified: 2026-09-11T03:16:24.450
Link: CVE-2026-89151
No data.