CVE-2026-11439 PUBLISHED

theonedev Parent Project projects improper authorization

Assigner: VulDB
Reserved: 05.06.2026 Published: 06.06.2026 Updated: 06.06.2026

A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the file /projects/ of the component Parent Project Handler. The manipulation of the argument project.parentId results in improper authorization. The attack may be performed from remote. Upgrading to version 15.0.6 can resolve this issue. It is recommended to upgrade the affected component.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 5.3

Product Status

Vendor theonedev
Product onedev
Versions
  • Version 15.0.0 is affected
  • Version 15.0.1 is affected
  • Version 15.0.2 is affected
  • Version 15.0.3 is affected
  • Version 15.0.4 is affected
  • Version 15.0.5 is affected
  • Version 15.0.6 is unaffected

Credits

  • aibot88 (VulDB User) reporter

References

Problem Types

  • Improper Authorization CWE
  • Incorrect Privilege Assignment CWE