Access Control Issues in Gitea Affecting Tag and Release Management
CVE-2026-105267
Currently unrated
What is CVE-2026-105267?
A vulnerability in Gitea allows users with write access to repository code to delete published releases, including attachments, without having the appropriate release management permission. This occurs through the shared handler for deleting tags and releases, which fails to adequately verify the type of tag being deleted. As a result, even users with restricted access can permanently erase important repository artifacts. Protected tag rules do not prevent the deletion of release tags, further compromising repository security and integrity.
Affected Version(s)
Gitea 0 <= 28.0.0
