Incorrect Privilege Assignment in Gitea - CVE-2026-73814
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges and transfer a repository.
The vulnerability exists due to incorrect privilege assignment in the collaboration access-mode endpoint when handling submitted collaboration permission changes. A remote privileged user can submit mode=4 to grant themselves effective Owner permissions to escalate privileges and transfer a repository.
The issue affects repositories owned by regular user accounts as well as organization-owned repositories.