Incorrect Authorization in Gerrit Code Review Software by Gerrit Code Review
CVE-2026-87720

7.6HIGH

Key Information:

Vendor

Gerrit

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-87720?

An incorrect authorization flaw has been identified in Gerrit Code Review that allows both authenticated and unauthenticated users to gain unauthorized access to private repository content. This vulnerability arises from an issue in the project name normalization and ProjectCache eviction logic. It permits crafted requests with multiple .git suffixes to bypass security measures. Specifically, the system only strips one terminal .git suffix from the project name, enabling potential unauthorized disclosures and the restoration of previously revoked administrative privileges. The issue affects several versions of the software, necessitating immediate updates to leverage the latest security patches.

Affected Version(s)

Gerrit 2.16.0 < 3.12.10

Gerrit 3.13.0 < 3.13.9

Gerrit 3.14.0 < 3.14.3

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jaime Cavero
.