← Back

CVE-2026-26231

nvd nist
Published: Jul 3, 2026Modified: Jul 7, 2026Deferred

JSON object

Loading...
8.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Exploitability: 3.1 / Impact: 4.7
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2 (Secondary)

Description

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.

References (6)

Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2

Timeline

No history available yet.