Description
Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
Published: 2026-09-11
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized privileged modification to repository settings
Action: Apply Patch
AI Analysis

Impact

Forgejo versions prior to 16.0.4 allow a restricted API token to invoke the "allow maintainer edit" feature in a way that was not intended, enabling the bearer of such a token to elevate privileges and modify repository configuration settings without being explicitly granted that level of access. This flaw creates an unauthorized modification vector that could be exploited to change settings, potentially exposing code or affecting repository behavior.

Affected Systems

Users running Forgejo before version 16.0.4 are vulnerable. The issue applies to all instances of the Forgejo repository management system that rely on the restricted API token mechanism for authentication.

Risk and Exploitability

The CVSS score of 3.5 indicates a low overall severity, and there is no EPSS score available, suggesting low but not negligible exploit probability. The vulnerability is not listed in CISA's KEV catalog, and no public exploits have been reported. An attacker would need possession of a restricted API token and knowledge of the affected API endpoint. The impact is confined to the scope of the token bearer, but misconfiguration could lead to unintended repository alterations.

Generated by OpenCVE AI on September 11, 2026 at 04:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Forgejo to version 16.0.4 or later to apply the vendor fix.
  • Revoke all restricted API tokens that were in use before the upgrade and issue new tokens with appropriate scopes.
  • Review and adjust repository permissions to ensure the "allow maintainer edit" feature is enabled only when necessary, and audit any recent configuration changes for suspicious activity.

Generated by OpenCVE AI on September 11, 2026 at 04:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Forgejo Restricted API Token Privilege Escalation

Fri, 11 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
First Time appeared Forgejo
Forgejo forgejo
Weaknesses CWE-863
CPEs cpe:2.3:a:forgejo:forgejo:*:*:*:*:*:*:*:*
Vendors & Products Forgejo
Forgejo forgejo
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T20:01:21.662Z

Reserved: 2026-09-11T02:23:27.533Z

Link: CVE-2026-89151

cve-icon Vulnrichment

Updated: 2026-09-11T20:01:06.321Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T03:16:24.450

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-89151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:30:05Z

Weaknesses