Privilege Escalation in Gitea LFS Affecting Gitea Users
CVE-2026-58435

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-58435?

A privilege escalation vulnerability in Gitea's LFS Deploy-Key feature has been identified, allowing unauthorized users to gain elevated privileges. This can lead to potential manipulation of access controls, impacting the security of repositories and user data. Users running affected versions are advised to upgrade to the latest version to mitigate this risk. For detailed information on the vulnerability and remediation steps, refer to the related GitHub security advisory and release notes.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

adrian-doyensec
.