Authorization bypass through user-controlled key in Gitea - CVE-2026-57886

 

Authorization bypass through user-controlled key in Gitea - CVE-2026-57886

Published: July 14, 2026


Vulnerability identifier: #VU137438
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-57886
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose private attachment content.

The vulnerability exists due to authorization bypass through user-controlled key in web issue/comment attachment handling when updating issue or comment attachments with attachment UUIDs. A remote user can submit a known attachment UUID through issue or comment edit flows to disclose private attachment content.

The issue can also alter the attachment's logical issue or comment association, and exploitation requires knowledge of a high-entropy attachment UUID.


Affected software

Gitea

How to mitigate CVE-2026-57886

Install security update from vendor's website.

Gitea - update to 1.27.0

External References

Related Security Bulletins