Junglewise Threat Intelligence

CVE-2026-27657: Gitea authorization bypass in primary email settings

CVE-2026-27657 · Severity: high · CVSS 7.5 · Published 2026-07-03

Technologies: code.gitea.io/gitea (Go), Gitea. Vendors: Go, Gitea.

Executive brief

Gitea, a self-hosted Git repository manager, contains an authorization flaw that allows any authenticated user to change another user's primary email address. This vulnerability can be exploited to take control of accounts, reset passwords via email, or intercept password recovery tokens—enabling full account takeover. Gitea versions before 1.25.5 are affected, and a patch is available.

Technical details

The vulnerability is an authorization bypass (CWE-639) in Gitea's email management API. The vulnerability allows an authenticated attacker to modify another user's primary email address without proper permission checks. The attack is network-accessible, requires no additional user interaction, and no special privileges. By changing a target user's primary email, an attacker can intercept password reset emails, two-factor authentication codes, or other account recovery mechanisms, leading to complete account compromise. The fix was released in version 1.25.5 and involves adding proper authorization checks to email update operations (PR #36586 and backport PR #36607).

Affected products

  • Gitea Gitea < 1.25.5

Timeline

  • 2026-07-03: disclosed: Published to GitHub Advisory Database
  • 2026-03-16: patched: Patch released in version 1.25.5 on March 16, 2026; advisory published July 3, 2026

References

Related threats