CVE-2026-89151 Overview
CVE-2026-89151 is an authorization flaw in Forgejo, the self-hosted Git forge, affecting versions before 16.0.4. Restricted API tokens can access the "allow maintainer edit" feature despite scope restrictions intended to prevent this access. The issue maps to [CWE-863: Incorrect Authorization]. Successful exploitation requires an authenticated attacker holding a low-privileged token and permits limited modification of pull request settings across repositories.
Critical Impact
Restricted API tokens gain unintended write access to the "allow maintainer edit" flag on pull requests, undermining scope-based token restrictions in Forgejo deployments.
Affected Products
- Forgejo versions prior to 16.0.4
- Forgejo 15.x branch prior to 15.0.8 release
- Self-hosted Forgejo Git forge instances
Discovery Timeline
- 2026-09-11 - CVE-2026-89151 published to the National Vulnerability Database
- 2026-09-11 - Last updated in NVD database
Technical Details for CVE-2026-89151
Vulnerability Analysis
Forgejo implements scoped API tokens to constrain what actions an authenticated caller can perform through the REST API. The token scope model is intended to enforce least privilege by restricting operations to explicitly granted resource categories. This vulnerability breaks that boundary for one specific endpoint related to pull request configuration.
The defect allows a restricted API token, which should lack authority over the target feature, to invoke the "allow maintainer edit" toggle on pull requests. That flag governs whether upstream maintainers can push commits to a contributor's pull request branch. An attacker abusing this flaw can enable or disable maintainer edit rights outside the intended token scope.
The impact is limited to integrity of pull request metadata. Confidentiality and availability are not directly affected, and no code execution occurs. The scope change in the CVSS vector reflects that a token constrained to one authorization domain influences a resource governed by another.
Root Cause
The root cause is missing scope enforcement in the handler responsible for the "allow maintainer edit" pull request setting. The endpoint checks that the caller is authenticated but does not validate that the presented token holds the scope required for the write operation. This is a classic [CWE-863] incorrect authorization pattern where authentication is conflated with authorization.
Attack Vector
Exploitation requires network access to a Forgejo instance and possession of any valid restricted API token. The attacker sends an authenticated API request to the pull request settings endpoint to modify the "allow maintainer edit" property. High attack complexity reflects the narrow set of preconditions and the limited nature of the operation exposed. Refer to the Forgejo Release Notes 15.0.8 and the Forgejo Milestone Update for the technical fix references.
Detection Methods for CVE-2026-89151
Indicators of Compromise
- API requests to pull request settings endpoints originating from tokens whose declared scopes do not include repository write permissions.
- Unexpected changes to the allow_maintainer_edit field on pull requests without corresponding UI activity from the pull request author.
- Audit log entries showing maintainer edit toggling by accounts that do not typically administer repositories.
Detection Strategies
- Correlate Forgejo access logs with token scope metadata to flag API calls that touch endpoints outside a token's granted scopes.
- Baseline normal usage patterns for pull request configuration endpoints and alert on anomalies from automation accounts.
- Review recent pull request state changes for the maintainer edit flag and compare against expected authoring behavior.
Monitoring Recommendations
- Forward Forgejo application and reverse proxy logs to a centralized analytics platform for long-term retention and query.
- Enable and monitor Forgejo's built-in audit logging for token issuance, token use, and pull request configuration events.
- Track outbound API activity from CI systems and third-party integrations that hold Forgejo tokens.
How to Mitigate CVE-2026-89151
Immediate Actions Required
- Upgrade Forgejo to version 16.0.4 or later, or to 15.0.8 on the 15.x branch, to remediate the authorization flaw.
- Inventory all issued API tokens and revoke any that are no longer needed or whose provenance is unclear.
- Rotate restricted API tokens used by shared automation to reduce residual risk from prior exposure.
Patch Information
The fix is delivered in Forgejo 16.0.4 and backported to 15.0.8. Consult the Forgejo Release Notes 15.0.8 and the Forgejo Milestone Update for the associated commits and change details.
Workarounds
- Restrict issuance of API tokens to a minimal set of trusted users until patches are applied.
- Place Forgejo behind a reverse proxy that can filter or rate-limit requests to pull request settings endpoints for suspect callers.
- Disable or minimize use of maintainer edit workflows where the integrity of that flag is business critical.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
