Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-56654: Gitea: Leaked Token Creates Full Access Tokens
CVE-2026-56654 · published 21 days ago
Summary
An attacker with a restricted Gitea token can create a full-access token without knowing the account password. This happens when the attacker passes the token in a specific format in the API request. To fix this, ensure that Gitea is updated to the latest version, which includes a patch for this issue.
What to do
- Update code.gitea.io gitea to version 1.27.0.
- Update gitea code.gitea.io/gitea to version 1.27.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | code.gitea.io | gitea |
< 1.27.0 Fix: upgrade to 1.27.0
|
| Go | gitea | code.gitea.io/gitea |
< 1.27.0 Fix: upgrade to 1.27.0
|
| – | gitea | gitea open source git server | <= 1.26.4 |
Original advisory text
Privilege Escalation via Access Token Scope Escalation in API
Privilege Escalation via Access Token Scope Escalation in API
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-683j-3ff6-hh2x
- https://github.com/go-gitea/gitea/pull/38406
- https://github.com/go-gitea/gitea/pull/38426
- https://github.com/go-gitea/gitea Product
- https://github.com/go-gitea/gitea/commit/de4b8277e9cb576f2315fb03b5ab6478b42a1d3...
- https://github.com/go-gitea/gitea/commit/f69e15afe7496cc62e96dab244629c69eb31a7b...
- https://github.com/go-gitea/gitea/releases/tag/v1.27.0
- https://github.com/advisories/GHSA-683j-3ff6-hh2x
- https://blog.gitea.com/gitea-1.27.0-is-released/
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56654... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-56654 Vendor Advisory
Severity
8.7
High
CVSS 4.0: 8.7 (GHSA)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
CWE-284Improper Access Control
Timeline
Published13 Aug 2026
Updated3 Sep 2026
First seen21 Jul 2026
Sources
GHSA-683j-3ff6-hh2x · GHSA
CVE-2026-56654 · NVD
GHSA-683j-3ff6-hh2x · OSV
CVE-2026-56654 · MITRE
CVE-2026-56654 · OSV
Monitor software like this
Free during beta