Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-101023: Gitea lets access token be used to get new tokens

CVE-2026-101023 · published 3 days ago
Summary

Gitea's login system can be tricked into treating a regular access token like a refresh token, allowing anyone who has that token to request fresh access and refresh tokens and stay logged in longer than intended. This can let an attacker keep access after the original token should have expired. Upgrade Gitea to the latest release that fixes the check and regenerate any existing tokens.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
gitea gitea <= 28.0.0
Original advisory text
Gitea OAuth2 refresh token grant accepts access tokens
Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the same OAuth2 application and grant could be exchanged for a new access token and refresh token. Whoever holds such an access token could keep access beyond the token's original lifetime.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-287Improper Authentication
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-101023 · MITRE
Track software like this
Free during beta