CVE-2026-92765

Source
https://cve.org/CVERecord?id=CVE-2026-92765
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92765.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92765
Published
2026-09-16T20:32:31Z
Modified
2026-09-19T03:30:37Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList
Details

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to retrieve complete web vulnerability data including titles, severities, statuses, and analyst notes from other tenants.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92765.json"
}
References

Affected packages

Git / github.com/archerysec/archerysec

Affected ranges

Type
GIT
Repo
https://github.com/archerysec/archerysec
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.0.6"
        },
        {
            "fixed": "2.0.6"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

ARCHERY-v1.*
ARCHERY-v1.0-beta
archerysec-v1.*
archerysec-v1.2
v1.*
v1.0
v1.1
v1.4
v1.5
v1.6
v1.7
v1.8
v1.9
v1.9.1
v2.*
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92765.json"