LOWVulnerability

CVE-2026-89151

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

Properties

severity
LOW
score
3.5
cve_id
CVE-2026-89151
signal_observed_at
2026-09-23T04:35:40+00:00
vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
published_at
2026-09-11T03:16:24.450
last_modified
2026-09-22T20:00:03.713

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-89151 — Ninja Signal Threat Intelligence | Ninja Signal