MEDIUM
opencve
CVE published 2026-09-16
CVE-2026-92764
OpenCVE before 3.1.0 has a vulnerability where the organizations API endpoint does not properly scope to the token's organization, allowing attackers with organization-scoped tokens to list and retrieve every organization their creator belongs to. This issue bypasses intended token isolation boundaries, potentially leading to unauthorized access to organization information. Defenders should assess exposur [truncated]