CVE-2026-91993

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identifiers from different workspaces to enumerate repository existence, determine repository type, and execute git ls-remote commands using other workspaces' stored credentials.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-15 12:17

Updated : 2026-09-15 12:17


NVD link : CVE-2026-91993

Mitre link : CVE-2026-91993

CVE.ORG link : CVE-2026-91993


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key