CVE-2026-92764: OpenCVE before 3.1.0 Organization API Ignores Token Scope

Published Sep 16, 2026
·
Updated

OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to, bypassing intended token isolation boundaries.

Affected Software

1 affected component
OpenCVE OpenCVE<3.1.0

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs an organization-scoped token created by a user who belongs to multiple organizations. The exposed organizations are the memberships of the user who created that token.

2

What information can be accessed?

The affected organizations API endpoint can list and retrieve every organization that the token creator belongs to, rather than limiting results to the organization assigned to the token. The provided data describes an information disclosure impact only.

3

Are default deployments affected?

The issue affects OpenCVE versions before 3.1.0 when organization-scoped tokens are used. The provided data does not state whether such tokens are enabled or created by default.

4

How can I determine whether my deployment is vulnerable?

Check whether the OpenCVE version is earlier than 3.1.0 and whether organization-scoped tokens exist for users with memberships in more than one organization. Such tokens may be able to retrieve organizations outside their intended scope.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203