Junglewise Threat Intelligence

CVE-2026-11438: theonedev OneDev improper authorization in project fork functionality

CVE-2026-11438 · Severity: medium · CVSS 6.3 · Published 2026-06-06

Technologies: OneDev. Vendors: OneDev.

Executive brief

OneDev, an open-source software development platform, contains a security flaw that allows users to bypass access controls when creating new projects. By manipulating project settings during creation, an authorized user can force the system to copy data from private repositories they are not supposed to see. This could lead to the unauthorized exposure of sensitive source code, project metadata, and internal development assets.

Technical details

An improper authorization vulnerability exists in OneDev's project creation workflow via the '/projects' endpoint. The application fails to validate if the requesting user has read permissions for the source project specified in the 'project.forkedFromId' argument. An attacker with project creation privileges can provide the ID of a private repository they cannot normally access; the system will then clone the repository data, LFS objects, and metadata into a new project owned by the attacker. Because the attacker is granted Owner-level permissions on the resulting fork, they can then read the copied contents. This issue is resolved in version 15.0.6.

Affected products

  • theonedev OneDev up to 15.0.5

Timeline

  • 2026-05-07: patched: Version 15.0.6 released
  • 2026-05-08: disclosed: Vulnerability details published by researcher
  • 2026-06-06: advisory: CVE-2026-11438 published

References

Related threats