Medium severity4.3NVD Advisory· Published Sep 16, 2026
CVE-2026-92764
CVE-2026-92764
Description
OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to, bypassing intended token isolation boundaries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/opencve/opencve/blob/v2.4.0/web/organizations/resources.pynvd
- github.com/opencve/opencve/blob/v3.1.0/web/organizations/resources.pynvd
- github.com/opencve/opencve/issues/744nvd
- github.com/opencve/opencve/releases/tag/v3.1.0nvd
- www.vulncheck.com/advisories/opencve-before-3.1.0-organization-api-ignores-token-scopenvd
News mentions
0No linked articles in our index yet.