Executive brief
Gitea is an open-source platform used by teams to host and manage software code. A security flaw was found where users with limited access could bypass restrictions to modify code in repositories they should only be able to read. This could allow an unauthorized person to change a project's source code, potentially introducing malicious changes or disrupting development operations.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Gitea's permission logic. The 'Allow edits from maintainers' path fails to properly validate write scopes, allowing users with read-only access to authorize and push commits to repositories they do not own. This is reachable via the network by an authenticated user. An attacker can exploit this to bypass branch protections or repository-level write restrictions to modify source code. The issue is resolved in Gitea version 1.26.2.
Affected products
- Gitea Gitea Open Source Git Server <= 1.26.1
Timeline
- 2026-04-29: patched: Fix merged into main and backported to 1.26 branch
- 2026-05-20: advisory: Gitea 1.26.2 release notes published
- 2026-07-03: disclosed: CVE-2026-26231 published to NVD