Gitea maintainer-edit permissions allow unauthorized commits to readable repositories
Summary
| CVE | CVE-2026-26231 |
|---|---|
| State | PUBLISHED |
| Assigner | Gitea |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-03 21:16:58 UTC |
| Updated | 2026-07-03 21:16:58 UTC |
| Description | Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write. |
Risk And Classification
Primary CVSS: v3.1 8.5 HIGH from 88ee5874-cf24-4952-aea0-31affedb7ff2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Problem Types: CWE-863 | CWE-863 CWE-863
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | Secondary | 8.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N |
| 3.1 | CNA | DECLARED | 8.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
LowIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Gitea | Gitea Open Source Git Server | affected 1.26.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/go-gitea/gitea/pull/37484 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | github.com | |
| github.com/go-gitea/gitea/pull/37479 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | github.com | |
| blog.gitea.com/release-of-1.26.2 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | blog.gitea.com | |
| github.com/go-gitea/gitea/releases/tag/v1.26.2 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | github.com | |
| github.com/go-gitea/gitea/security/advisories/GHSA-mm7c-rhg6-qr4r | 88ee5874-cf24-4952-aea0-31affedb7ff2 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: ddd (en)
There are currently no legacy QID mappings associated with this CVE.