Description
OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to, bypassing intended token isolation boundaries.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Organization Data
Action: Apply Patch
AI Analysis

Impact

This vulnerability occurs because OpenCVE versions before 3.1.0 do not correctly enforce the organization scope of the API token. When a token is created with a specific organization scope, the organizations endpoint still returns all of the token creator’s memberships, allowing the bearer to discover and retrieve data about every organization the token’s owner belongs to. The impact is the exposure of sensitive organizational membership information and the potential for further downstream compromise if those organizations contain critical resources.

Affected Systems

The affected product is OpenCVE, specifically all releases older than version 3.1.0. Users running v2.4.0 or any earlier build will be vulnerable, as the fix was introduced in the 3.1.0 release. No other vendors or products are impacted according to the CNA data.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a very low but nonzero likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. An attacker who can obtain an organization‑scoped token—such as a legitimate user or an insider—can enumerate the organization memberships of the token’s creator, bypassing the intended isolation boundaries between organizations. The attack requires only possession of a valid token; no additional exploits or vulnerabilities are needed.

Generated by OpenCVE AI on September 23, 2026 at 21:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenCVE to version 3.1.0 or later to apply the token‑scoping fix.
  • If an upgrade is not currently possible, revoke all organization‑scoped tokens, re‑issue new tokens with stricter scopes, and enforce access control policies that validate the token scope against the organization requested.
  • Monitor API logs for anomalous organization‑listing activity and investigate any unexpected token usage.

Generated by OpenCVE AI on September 23, 2026 at 21:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 19:30:00 +0000


Wed, 23 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to, bypassing intended token isolation boundaries. OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to, bypassing intended token isolation boundaries.
Title OpenCVE before 3.1.0 Organization API Ignores Token Scope OpenCVE 2.4.0 < 3.1.0 Organization API Ignores Token Scope
References

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Opencve
Opencve opencve
Vendors & Products Opencve
Opencve opencve

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organization their creator belongs to, bypassing intended token isolation boundaries.
Title OpenCVE before 3.1.0 Organization API Ignores Token Scope
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-26T13:30:00.117Z

Reserved: 2026-09-16T19:06:21.593Z

Link: CVE-2026-92764

cve-icon Vulnrichment

Updated: 2026-09-21T16:22:42.544Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:25.303

Modified: 2026-09-23T19:19:44.587

Link: CVE-2026-92764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T21:15:09Z

Weaknesses