Off-by-One Error in Gogs Git Service Allows Privilege Escalation
CVE-2026-52804
5.5MEDIUM
What is CVE-2026-52804?
An off-by-one error in the ChangeCollaborationAccessMode function of Gogs, a self-hosted Git service, allows repository admin collaborators to escalate their access level to owner status. This issue has been resolved in version 0.14.3. Administrators are advised to update their Gogs installations to ensure they are protected from potential misuse of this vulnerability.
Affected Version(s)
gogs < 0.14.3
