Off-by-One Error in Gogs Git Service Allows Privilege Escalation
CVE-2026-52804

5.5MEDIUM

Key Information:

Vendor

Gogs

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2026-52804?

An off-by-one error in the ChangeCollaborationAccessMode function of Gogs, a self-hosted Git service, allows repository admin collaborators to escalate their access level to owner status. This issue has been resolved in version 0.14.3. Administrators are advised to update their Gogs installations to ensure they are protected from potential misuse of this vulnerability.

Affected Version(s)

gogs < 0.14.3

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.