top of page
perceptive_background_267k.jpg

Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit…

Published:

2 juli 2026 om 22:00:00

Alert date:

3 juli 2026 om 22:04:52

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2026-28740 affects Gitea versions up to and including 1.26.2, where a flaw in Git LFS object reuse allows unauthorized access to private source objects. Users who have repository access but lack Code-unit access can exploit this vulnerability to view private LFS objects they should not be permitted to access. The issue stems from improper authorization checks during LFS object reuse operations. Gitea has released versions 1.26.3 and 1.26.4 to address this vulnerability. A security advisory has been published on GitHub alongside a pull request detailing the fix. Users are strongly advised to upgrade to the patched versions immediately to prevent potential unauthorized data exposure.

Technical details

Mitigation steps:

Affected products:

Gitea 1.26.2 and earlier

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page