PatchSiren

opencve CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM opencve CVE published 2026-09-16

CVE-2026-92764

OpenCVE before 3.1.0 has a vulnerability where the organizations API endpoint does not properly scope to the token's organization, allowing attackers with organization-scoped tokens to list and retrieve every organization their creator belongs to. This issue bypasses intended token isolation boundaries, potentially leading to unauthorized access to organization information. Defenders should assess exposur [truncated]