2026-06-06 17:0CVE-2026-11438VulDB
PUBLISHED5.2ApplicationCWE-285CWE-266

theonedev projects improper authorization

A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument project.forkedFromId leads to improper authorization. The attack is possible to be carried out remotely. Upgrading to version 15.0.6 addresses this issue. Upgrading the affected component is recommended.

Problem type

Affected products

theonedev

onedev

15.0.0 - AFFECTED

15.0.1 - AFFECTED

15.0.2 - AFFECTED

15.0.3 - AFFECTED

15.0.4 - AFFECTED

15.0.5 - AFFECTED

15.0.6 - UNAFFECTED

References

GitHub Security Advisories

GHSA-w3rp-rgp7-p999

A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability...

https://github.com/advisories/GHSA-w3rp-rgp7-p999

A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument project.forkedFromId leads to improper authorization. The attack is possible to be carried out remotely. Upgrading to version 15.0.6 addresses this issue. Upgrading the affected component is recommended.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-11438
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-11438",
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "dateUpdated": "2026-06-06T17:00:14.794Z",
    "dateReserved": "2026-06-05T22:21:00.483Z",
    "datePublished": "2026-06-06T17:00:14.794Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB",
        "dateUpdated": "2026-06-06T17:00:14.794Z"
      },
      "title": "theonedev projects improper authorization",
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument project.forkedFromId leads to improper authorization. The attack is possible to be carried out remotely. Upgrading to version 15.0.6 addresses this issue. Upgrading the affected component is recommended."
        }
      ],
      "affected": [
        {
          "vendor": "theonedev",
          "product": "onedev",
          "cpes": [
            "cpe:2.3:a:theonedev:onedev:*:*:*:*:*:*:*:*"
          ],
          "versions": [
            {
              "version": "15.0.0",
              "status": "affected"
            },
            {
              "version": "15.0.1",
              "status": "affected"
            },
            {
              "version": "15.0.2",
              "status": "affected"
            },
            {
              "version": "15.0.3",
              "status": "affected"
            },
            {
              "version": "15.0.4",
              "status": "affected"
            },
            {
              "version": "15.0.5",
              "status": "affected"
            },
            {
              "version": "15.0.6",
              "status": "unaffected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Improper Authorization",
              "cweId": "CWE-285",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Incorrect Privilege Assignment",
              "cweId": "CWE-266",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://vuldb.com/vuln/369018",
          "name": "VDB-369018 | theonedev projects improper authorization",
          "tags": [
            "vdb-entry",
            "technical-description"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/369018/cti",
          "name": "VDB-369018 | CTI Indicators (IOB, IOC, TTP, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-11438",
          "name": "CVE-2026-11438 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/822944",
          "name": "Submit #822944 | theonedev onedev 15.05 BOPLA",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://www.cnblogs.com/aibot/p/19994142",
          "tags": [
            "related"
          ]
        },
        {
          "url": "https://github.com/theonedev/onedev/releases/tag/v15.0.6",
          "tags": [
            "patch"
          ]
        }
      ],
      "metrics": [
        {},
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM"
          }
        },
        {
          "cvssV3_0": {
            "version": "3.0",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM"
          }
        },
        {
          "cvssV2_0": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C",
            "baseScore": 6.5
          }
        }
      ],
      "timeline": [
        {
          "time": "2026-06-05T02:00:00.000Z",
          "lang": "en",
          "value": "VulDB entry created"
        },
        {
          "time": "2026-06-06T00:00:00.000Z",
          "lang": "en",
          "value": "Advisory disclosed"
        },
        {
          "time": "2026-06-06T00:26:13.000Z",
          "lang": "en",
          "value": "VulDB entry last update"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "aibot88 (VulDB User)",
          "type": "reporter"
        }
      ]
    }
  }
}