What is CVE-2026-57897?
CVE-2026-57897 allows cross-repository information disclosure through org-level Actions run/job APIs. Attackers might gain unauthorized access to sensitive workflow data across repositories within an organization, so it is recommended to immediately review API access controls.
Azərbaycanca: CVE-2026-57897 boşluğu təşkilat səviyyəli Actions API-ləri vasitəsilə müxtəlif repozitoriyalar arasında məlumat sızmasına imkan verir. Bu zəiflik təşkilat daxilindəki həssas iş axını məlumatlarının icazəsiz əldə edilməsinə səbəb ola bilər, ona görə də dərhal API giriş nəzarətlərini nəzərdən keçirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What type of data can be disclosed through the CVE-2026-57897 vulnerability?
This vulnerability allows unauthorized access to sensitive workflow data across repositories within an organization through org-level Actions run/job APIs.
What security measure is recommended for CVE-2026-57897?
It is recommended to immediately review API access controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.