CVE-2026-91993

Source
https://cve.org/CVERecord?id=CVE-2026-91993
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91993.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-91993
Published
2026-09-15T11:35:48Z
Modified
2026-09-17T03:47:27Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Jpom through 2.11.12 Workspace Isolation Bypass via /build/branch-list
Details

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identifiers from different workspaces to enumerate repository existence, determine repository type, and execute git ls-remote commands using other workspaces' stored credentials.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91993.json"
}
References

Affected packages

Git / github.com/dromara/jpom

Affected ranges

Type
GIT
Repo
https://github.com/dromara/jpom
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.11.12"
        },
        {
            "fixed": "2.11.12"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

2.*
2.4.4
fix-2.*
fix-2.8.0
Other
stand-alone
v1.*
v1.0
v1.1
v2.*
v2.0
v2.1
v2.10.0
v2.10.1
v2.10.10
v2.10.11
v2.10.12
v2.10.13
v2.10.14
v2.10.15
v2.10.17
v2.10.18
v2.10.19
v2.10.2
v2.10.20
v2.10.21
v2.10.23
v2.10.24
v2.10.25
v2.10.26
v2.10.27
v2.10.28
v2.10.29
v2.10.3
v2.10.30
v2.10.31
v2.10.33
v2.10.34
v2.10.35
v2.10.36
v2.10.37
v2.10.38
v2.10.4
v2.10.41
v2.10.42
v2.10.43
v2.10.44
v2.10.45
v2.10.47
v2.10.5
v2.10.6
v2.10.7
v2.10.8
v2.10.9
v2.11.0
v2.11.1
v2.11.10
v2.11.11
v2.11.2
v2.11.3
v2.11.4
v2.11.5
v2.11.6
v2.11.7
v2.11.9
v2.2
v2.3.1
v2.3.2
v2.4.0
v2.4.1
v2.4.1-patch
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.5.2
v2.6.1
v2.7.0
v2.8.0
v2.8.0-fix
v2.8.1
v2.8.10
v2.8.11
v2.8.12
v2.8.13
v2.8.14
v2.8.15
v2.8.16
v2.8.17
v2.8.18
v2.8.2
v2.8.21
v2.8.22
v2.8.23
v2.8.24
v2.8.25
v2.8.3
v2.8.4
v2.8.5
v2.8.6
v2.8.7
v2.8.8
v2.8.9
v2.9.0
v2.9.1
v2.9.10
v2.9.11
v2.9.12
v2.9.13
v2.9.14
v2.9.15
v2.9.16
v2.9.17
v2.9.18
v2.9.19
v2.9.2
v2.9.20
v2.9.21
v2.9.3
v2.9.4
v2.9.5
v2.9.6
v2.9.7
v2.9.8
v2.9.9
v2.9.9.fix

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91993.json"