Authorization Bypass and Sensitive Information Exposure in Gitea by Gitea
CVE-2026-58432

5.9MEDIUM

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58432?

A significant security flaw in Gitea arises from a missing authorization check and an incorrect permission assignment, which could allow unauthorized actors to access sensitive resources. This vulnerability enables attackers to bypass standard authorization mechanisms, leading to potential exposure of confidential data and system integrity risks. Users are urged to upgrade to the latest version to mitigate this risk.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

z3r0s6
.