A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument project.forkedFromId leads to improper authorization. The attack is possible to be carried out remotely. Upgrading to version 15.0.6 addresses this issue. Upgrading the affected component is recommended.
theonedev projects improper authorization
Problem type
Affected products
theonedev
15.0.0 - AFFECTED
15.0.1 - AFFECTED
15.0.2 - AFFECTED
15.0.3 - AFFECTED
15.0.4 - AFFECTED
15.0.5 - AFFECTED
15.0.6 - UNAFFECTED
References
https://vuldb.com/vuln/369018
https://vuldb.com/vuln/369018/cti
https://vuldb.com/cve/CVE-2026-11438
https://vuldb.com/submit/822944
https://www.cnblogs.com/aibot/p/19994142
https://github.com/theonedev/onedev/releases/tag/v15.0.6
GitHub Security Advisories
GHSA-w3rp-rgp7-p999
A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability...
https://github.com/advisories/GHSA-w3rp-rgp7-p999A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument project.forkedFromId leads to improper authorization. The attack is possible to be carried out remotely. Upgrading to version 15.0.6 addresses this issue. Upgrading the affected component is recommended.
https://nvd.nist.gov/vuln/detail/CVE-2026-11438
https://github.com/theonedev/onedev/releases/tag/v15.0.6
https://vuldb.com/cve/CVE-2026-11438
https://vuldb.com/submit/822944
https://vuldb.com/vuln/369018
https://vuldb.com/vuln/369018/cti
https://www.cnblogs.com/aibot/p/19994142
https://github.com/advisories/GHSA-w3rp-rgp7-p999
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-11438Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-11438",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-06-06T17:00:14.794Z",
"dateReserved": "2026-06-05T22:21:00.483Z",
"datePublished": "2026-06-06T17:00:14.794Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-06-06T17:00:14.794Z"
},
"title": "theonedev projects improper authorization",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument project.forkedFromId leads to improper authorization. The attack is possible to be carried out remotely. Upgrading to version 15.0.6 addresses this issue. Upgrading the affected component is recommended."
}
],
"affected": [
{
"vendor": "theonedev",
"product": "onedev",
"cpes": [
"cpe:2.3:a:theonedev:onedev:*:*:*:*:*:*:*:*"
],
"versions": [
{
"version": "15.0.0",
"status": "affected"
},
{
"version": "15.0.1",
"status": "affected"
},
{
"version": "15.0.2",
"status": "affected"
},
{
"version": "15.0.3",
"status": "affected"
},
{
"version": "15.0.4",
"status": "affected"
},
{
"version": "15.0.5",
"status": "affected"
},
{
"version": "15.0.6",
"status": "unaffected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Improper Authorization",
"cweId": "CWE-285",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Incorrect Privilege Assignment",
"cweId": "CWE-266",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/369018",
"name": "VDB-369018 | theonedev projects improper authorization",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/369018/cti",
"name": "VDB-369018 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-11438",
"name": "CVE-2026-11438 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/822944",
"name": "Submit #822944 | theonedev onedev 15.05 BOPLA",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://www.cnblogs.com/aibot/p/19994142",
"tags": [
"related"
]
},
{
"url": "https://github.com/theonedev/onedev/releases/tag/v15.0.6",
"tags": [
"patch"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
"baseScore": 6.3,
"baseSeverity": "MEDIUM"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
"baseScore": 6.3,
"baseSeverity": "MEDIUM"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C",
"baseScore": 6.5
}
}
],
"timeline": [
{
"time": "2026-06-05T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-06-06T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-06-06T00:26:13.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "aibot88 (VulDB User)",
"type": "reporter"
}
]
}
}
}