CVE-2026-11439
published 2026-06-06CVE-2026-11439: A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the file /projects/ of the component Parent…
PriorityP340medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.21%
11.7th percentile
A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the file /projects/ of the component Parent Project Handler. The manipulation of the argument project.parentId results in improper authorization. The attack may be performed from remote. Upgrading to version 15.0.6 can resolve this issue. It is recommended to upgrade the affected component.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| theonedev | onedev | — | — |
| theonedev | onedev | — | — |
| theonedev | onedev | — | — |
| theonedev | onedev | — | — |
| theonedev | onedev | — | — |
| theonedev | onedev | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
theonedev up to 15.0.5 Parent Project /projects/ project.parentId improper authorization
vuldb·2026-06-06·CVSS 6.3
CVE-2026-11439 [MEDIUM] theonedev up to 15.0.5 Parent Project /projects/ project.parentId improper authorization
A vulnerability was found in theonedev onedev up to 15.0.5. It has been declared as critical. Affected by this issue is some unknown functionality of the file /projects/ of the component Parent Project Handler. The manipulation of the argument project.parentId results in improper authorization.
This vulnerability was named CVE-2026-11439. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
A vulnerability was found in theonedev onedev up to 15.0.5.
ghsa_unreviewed·2026-06-06
CVE-2026-11439 [MEDIUM] CWE-266 A vulnerability was found in theonedev onedev up to 15.0.5.
A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the file /projects/ of the component Parent Project Handler. The manipulation of the argument project.parentId results in improper authorization. The attack may be performed from remote. Upgrading to version 15.0.6 can resolve this issue. It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-06
Published