Privilege Escalation in Gitea LFS Affecting Gitea Users
CVE-2026-58435

5.4MEDIUM

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58435?

A privilege escalation vulnerability in Gitea's LFS Deploy-Key feature has been identified, allowing unauthorized users to gain elevated privileges. This can lead to potential manipulation of access controls, impacting the security of repositories and user data. Users running affected versions are advised to upgrade to the latest version to mitigate this risk. For detailed information on the vulnerability and remediation steps, refer to the related GitHub security advisory and release notes.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

adrian-doyensec
.