CVE-2026-89151: Low severity Forgejo Forgejo vulnerability
Published Sep 11, 2026
·Updated
Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
Affected Software
1 affected component
Forgejo Forgejo<16.0.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Forgejoto a version that resolves this vulnerability.Fixed in 16.0.4
Event History
Sep 11, 2026
CVE Published
via MITRE·02:23 AM
Data Sourced
via MITRE·02:23 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs a restricted API token. The vulnerability does not describe exploitation with an unauthenticated token or without API access.
2
Which deployments are affected?
Forgejo versions before 16.0.4 are affected. The provided information does not state whether any particular token restriction or repository setting is enabled by default.
3
What capability could be accessed unexpectedly?
A restricted API token may be used for unintended access to the “allow maintainer edit” feature. The available information does not specify additional impact beyond integrity effects.