Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-58433: GitHub Repository Access Bypass in GitHub Organizations
CVE-2026-58433 · published 1 day ago
Summary
The Team-repository linking endpoint in GitHub Organizations does not respect the organization's settings for team access. This could allow unauthorized access to repositories, potentially leading to data breaches or unauthorized changes. To protect your organization, ensure that you have properly configured team access and review your organization's settings regularly.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gitea | gitea open source git server | <= 1.26.4 |
Original advisory text
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published13 Aug 2026
Updated14 Aug 2026
First seen13 Aug 2026
Monitor software like this
Free during beta