CVE-2026-58429CWE-1259CWE-284broken-access-control
CVE-2026-58429
Medium · published August 13, 2026
What it is
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
The record
Technical detail
- CVSS v3.1
- 4.9 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00346 · 27.5th percentile
- Weaknesses
- CWE-1259 · Improper Restriction of Security Token Assignment; CWE-284 · Improper Access Control
- Published
- 2026-08-13T21:17Z
References (4)
EPSS history
Timeline