CVE-2026-11441
Received Received - Intake
Improper Authorization in OneDev up to 15.0.5

Publication date: 2026-06-06

Last updated on: 2026-06-06

Assigner: VulDB

Description
A vulnerability was identified in theonedev onedev up to 15.0.5. This vulnerability affects the function canAccessIssue of the file /issues/ of the component Pull Request Handler. Such manipulation of the argument issue leads to improper authorization. It is possible to launch the attack remotely. Upgrading to version 15.0.6 is able to resolve this issue. It is advisable to upgrade the affected component.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-06
Last Modified
2026-06-06
Generated
2026-06-06
AI Q&A
2026-06-06
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
theonedev onedev to 15.0.5 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability involves improper authorization in the canAccessIssue function, which could allow unauthorized access to issue data remotely.

Such unauthorized access to potentially sensitive project management and issue tracking information may lead to exposure of confidential data.

Exposure of sensitive or personal data due to improper authorization could impact compliance with data protection regulations such as GDPR or HIPAA, which require strict access controls to protect personal and sensitive information.

Therefore, this vulnerability could pose a risk to compliance with these standards if exploited, by enabling unauthorized data access.

Upgrading to version 15.0.6 is recommended to resolve this issue and help maintain compliance.


Can you explain this vulnerability to me?

This vulnerability exists in theonedev onedev versions up to 15.0.5, specifically in the function canAccessIssue within the /issues/ file of the Pull Request Handler component. The issue arises from improper authorization due to manipulation of the argument 'issue'. This flaw allows an attacker to remotely exploit the system by bypassing proper access controls.

Upgrading to version 15.0.6 resolves this vulnerability.


How can this vulnerability impact me? :

This vulnerability can lead to unauthorized access to issues within the affected system, potentially exposing sensitive information or allowing unauthorized actions on pull requests. Since the attack can be launched remotely, it increases the risk of exploitation without physical access.


What immediate steps should I take to mitigate this vulnerability?

The immediate step to mitigate this vulnerability is to upgrade the affected component, theonedev onedev, to version 15.0.6 or later.

This upgrade resolves the improper authorization issue in the canAccessIssue function of the Pull Request Handler component.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart