Junglewise Threat Intelligence

CVE-2026-56654: Gitea privilege escalation via access token scope escalation in API

CVE-2026-56654 · Severity: high · CVSS 4 · Published 2026-07-21

Technologies: code.gitea.io/gitea (Go), Gitea, gitea.dev (Go). Vendors: Go, Gitea.

Executive brief

Gitea is an open-source platform for hosting software development projects. A security flaw in its programming interface (API) allows an attacker who has a limited-access token (such as one used for automated testing) to create a new, fully-privileged token. This allows the attacker to gain complete control over a user's account and data without needing to know their password.

Technical details

A privilege escalation vulnerability exists in Gitea's API due to a logic error in the authentication middleware. The `reqBasicOrRevProxyAuth` middleware, intended to require password-based authentication for sensitive operations like token creation, can be bypassed by providing a Personal Access Token (PAT) in the `Authorization: Basic <token>:x-oauth-basic` format. The backend incorrectly sets `IsBasicAuth=true` for these requests. Furthermore, the `CreateAccessToken` handler fails to implement a 'scope ceiling' check, allowing a caller with a restricted token to mint a new token with the 'all' scope. This allows an attacker with any valid token to escalate to full account privileges. Fixed in version 1.27.0.

Affected products

  • Gitea Gitea < 1.27.0

Timeline

  • 2026-07-13: disclosed
  • 2026-07-21: advisory

References

Related threats