High severity8.5GHSA Advisory· Published Jul 3, 2026· Updated Jul 7, 2026
CVE-2026-26231
CVE-2026-26231
Description
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
code.gitea.io/giteaGo | < 1.26.2 | 1.26.2 |
Affected products
2- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
6News mentions
1- Gitea: Ten CVEs Disclosed Together, Seven High-Severity Token-Scope and Auth Bypass FlawsVypr Intelligence · Jun 17, 2026