Executive brief
Gitea, a popular self-hosted Git service, was found to have a security flaw in how it handles issue templates. The system failed to properly check user permissions when accessing issue-template information through its programming interface (API). This could allow an authenticated user to view information they are not authorized to see, potentially exposing internal project details.
Technical details
A missing authorization vulnerability (CWE-862) exists in Gitea's issue-template API endpoints. The software fails to verify repository-unit permissions, allowing authenticated users to bypass intended access controls. An attacker with network access and a valid user account can exploit this to read issue templates from repositories they should not have access to. The issue is resolved in Gitea version 1.26.2.
Affected products
- Gitea Gitea Open Source Git Server <= 1.26.1
Timeline
- 2026-05-20: patched: Gitea version 1.26.2 released
- 2026-07-03: disclosed: CVE-2026-27783 published