Incorrect authorization in Gitea - CVE-2026-58431

 

Incorrect authorization in Gitea - CVE-2026-58431

Published: July 14, 2026


Vulnerability identifier: #VU137434
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58431
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the /api/v1/teams/{id} API routes when handling requests with a public-only access token. A remote user can send crafted API requests to disclose sensitive information.

Private team repository metadata and private team activity feed entries may be exposed through affected team endpoints.


Affected software

Gitea

How to mitigate CVE-2026-58431

Install security update from vendor's website.

Gitea - update to 1.27.0

External References

Related Security Bulletins