Description
Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identifiers from different workspaces to enumerate repository existence, determine repository type, and execute git ls-remote commands using other workspaces' stored credentials.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Unauthorized Access to Other Workspaces via Access Control Bypass
Action: Update
AI Analysis

Impact

This is a CWE-639 authorization bypass vulnerability. Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identifiers from different workspaces to enumerate repository existence, determine repository type, and execute git ls-remote commands using other workspaces' stored credentials. The vulnerability does not provide arbitrary code execution but enables information disclosure and credential misuse.

Affected Systems

The affected product is Jpom by dromara. Any deployment of Jpom up to and including version 2.11.12 is vulnerable. Versions beyond 2.11.12 are presumed fixed, but administrators should verify the repository version and apply the latest release.

Risk and Exploitability

The CVSS score of 5.3 signals moderate severity. The EPSS score of 0.00251 indicates a very low but non‑zero likelihood that attackers will successfully exploit the flaw. The vulnerability is not in the CISA KEV catalog. Because the attacker must be authenticated, the risk is limited to users with legitimate access. However, the flaw permits enumeration of repositories in other workspaces, determination of their types, and execution of git ls-remote commands using the target workspace’s stored credentials, which can leak sensitive data and potentially enable further credential misuse.

Generated by OpenCVE AI on September 17, 2026 at 17:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Jpom to a version newer than 2.11.12 that implements correct workspace ownership checks on /build/branch-list.
  • Restrict access to the /build/branch-list endpoint for users who do not have explicit workspace permissions, leveraging the application’s role‑based access logs for unexpected repositoryId requests from users, and investigate any patterns that suggest attempts to enumerate or access other workspaces.
  • Temporarily disable the /build/branch-list endpoint for all non‑admin users until the vulnerability is patched.

Generated by OpenCVE AI on September 17, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identifiers from different workspaces to enumerate repository existence, determine repository type, and execute git ls-remote commands using other workspaces' stored credentials.
Title Jpom through 2.11.12 Workspace Isolation Bypass via /build/branch-list
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:32.765Z

Reserved: 2026-09-15T11:11:13.311Z

Link: CVE-2026-91993

cve-icon Vulnrichment

Updated: 2026-09-17T18:38:15.683Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T12:17:54.640

Modified: 2026-09-23T17:17:44.853

Link: CVE-2026-91993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key