


Perceptive Security
SOC/SIEM Consultancy

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit…
Published:
2 juli 2026 om 22:00:00
Alert date:
3 juli 2026 om 22:04:52
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-28740 affects Gitea versions up to and including 1.26.2, where a flaw in Git LFS object reuse allows unauthorized access to private source objects. Users who have repository access but lack Code-unit access can exploit this vulnerability to view private LFS objects they should not be permitted to access. The issue stems from improper authorization checks during LFS object reuse operations. Gitea has released versions 1.26.3 and 1.26.4 to address this vulnerability. A security advisory has been published on GitHub alongside a pull request detailing the fix. Users are strongly advised to upgrade to the patched versions immediately to prevent potential unauthorized data exposure.
Technical details
Mitigation steps:
Affected products:
Gitea 1.26.2 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-28740
https://blog.gitea.com/release-of-1.26.3-and-1.26.4/
https://github.com/go-gitea/gitea/pull/38050
https://github.com/go-gitea/gitea/releases/tag/v1.26.3
https://github.com/go-gitea/gitea/security/advisories/GHSA-2m9v-5q2g-58vq
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
