CVE-2026-103504
N/A
N/A
Summary
Changing an organization team's permission through the API with only the permission field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gitea | Gitea | 0 <= 1.27.3 | affected |
Weaknesses
- CWE-272: CWE-272: Least Privilege Violation
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-x8c3-3rp8-2j46
- https://github.com/go-gitea/gitea/pull/38938
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.