Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-56654: Gitea: Leaked Token Creates Full Access Tokens

CVE-2026-56654 · published 21 days ago
Summary

An attacker with a restricted Gitea token can create a full-access token without knowing the account password. This happens when the attacker passes the token in a specific format in the API request. To fix this, ensure that Gitea is updated to the latest version, which includes a patch for this issue.

What to do
  • Update code.gitea.io gitea to version 1.27.0.
  • Update gitea code.gitea.io/gitea to version 1.27.0.
Affected software
Ecosystem VendorProductAffected versions
go code.gitea.io gitea < 1.27.0
Fix: upgrade to 1.27.0
Go gitea code.gitea.io/gitea < 1.27.0
Fix: upgrade to 1.27.0
– gitea gitea open source git server <= 1.26.4
Original advisory text
Privilege Escalation via Access Token Scope Escalation in API
Privilege Escalation via Access Token Scope Escalation in API
Severity
8.7 High
CVSS 4.0: 8.7 (GHSA)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
CWE-284Improper Access Control
Timeline
Published13 Aug 2026
Updated3 Sep 2026
First seen21 Jul 2026
Monitor software like this
Free during beta