CVE-2026-11441

Source
https://cve.org/CVERecord?id=CVE-2026-11441
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11441.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-11441
Published
2026-06-06T17:45:10.650Z
Modified
2026-07-25T03:56:43.871013594Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
theonedev Pull Request issues canAccessIssue improper authorization
Details

A vulnerability was identified in theonedev onedev up to 15.0.5. This vulnerability affects the function canAccessIssue of the file /issues/ of the component Pull Request Handler. Such manipulation of the argument issue leads to improper authorization. It is possible to launch the attack remotely. Upgrading to version 15.0.6 is able to resolve this issue. It is advisable to upgrade the affected component.

Database specific
{
    "cwe_ids": [
        "CWE-266",
        "CWE-285"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11441.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/theonedev/onedev

Affected ranges

Type
GIT
Repo
https://github.com/theonedev/onedev
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "15.0.0"
        },
        {
            "last_affected": "15.0.0"
        },
        {
            "introduced": "15.0.1"
        },
        {
            "last_affected": "15.0.1"
        },
        {
            "introduced": "15.0.2"
        },
        {
            "last_affected": "15.0.2"
        },
        {
            "introduced": "15.0.3"
        },
        {
            "last_affected": "15.0.3"
        },
        {
            "introduced": "15.0.4"
        },
        {
            "last_affected": "15.0.4"
        },
        {
            "introduced": "15.0.5"
        },
        {
            "last_affected": "15.0.5"
        }
    ]
}

Affected versions

15.*
15.0.0
15.0.1
15.0.2
15.0.3
15.0.4
15.0.5
v15.*
v15.0.0
v15.0.1
v15.0.2
v15.0.3
v15.0.4
v15.0.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11441.json"