PoC Index

CVE-2026-26231

HIGH 8.5EPSS 0.4%

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.

CVSS v3.1
8.5 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
CVSS v3.1
8.5 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
EPSS
0.35% chance of exploitation in the next 30 days, 28th percentile
Published
2026-07-03
Updated
2026-07-07

Proof-of-concept exploits (1)

References

Related