


Perceptive Security
SOC/SIEM Consultancy

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but…
Published:
2 juli 2026 om 22:00:00
Alert date:
3 juli 2026 om 22:04:52
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Supply Chain & Dependencies
CVE-2026-26231 affects Gitea versions up to and including 1.26.1, where the 'Allow edits from maintainers' permission feature can be exploited to authorize commits to repositories that a user should only have read access to. This represents an improper access control vulnerability that allows unauthorized write operations. The vulnerability was patched in Gitea version 1.26.2. Multiple GitHub pull requests (37479 and 37484) were merged to address this issue. A security advisory was published under GHSA-mm7c-rhg6-qr4r. The flaw could allow attackers to commit malicious code to repositories they should not be able to modify. Organizations using Gitea for source code management should upgrade to version 1.26.2 immediately. The vulnerability impacts the integrity of hosted repositories and the software supply chain.
Technical details
Mitigation steps:
Affected products:
Gitea 1.26.1 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-26231
https://blog.gitea.com/release-of-1.26.2/
https://github.com/go-gitea/gitea/pull/37479
https://github.com/go-gitea/gitea/pull/37484
https://github.com/go-gitea/gitea/releases/tag/v1.26.2
https://github.com/go-gitea/gitea/security/advisories/GHSA-mm7c-rhg6-qr4r
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
