{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-26231","assignerOrgId":"88ee5874-cf24-4952-aea0-31affedb7ff2","state":"PUBLISHED","assignerShortName":"Gitea","dateReserved":"2026-03-03T03:25:59.965Z","datePublished":"2026-07-03T20:19:34.133Z","dateUpdated":"2026-07-07T16:59:29.212Z"},"containers":{"cna":{"title":"Gitea maintainer-edit permissions allow unauthorized commits to readable repositories","descriptions":[{"lang":"en","value":"Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write."}],"affected":[{"vendor":"Gitea","product":"Gitea Open Source Git Server","versions":[{"version":"0","lessThanOrEqual":"1.26.1","status":"affected","versionType":"semver"}],"defaultStatus":"unaffected"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-863","description":"CWE-863","lang":"en","type":"CWE"}]}],"references":[{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-mm7c-rhg6-qr4r","name":"GitHub Security Advisory","tags":["vendor-advisory"]},{"url":"https://github.com/go-gitea/gitea/pull/37479","name":"GitHub Pull Request #37479","tags":["patch"]},{"url":"https://github.com/go-gitea/gitea/pull/37484","name":"GitHub Pull Request #37484","tags":["patch"]},{"url":"https://github.com/go-gitea/gitea/releases/tag/v1.26.2","name":"Gitea v1.26.2 Release","tags":["release-notes"]},{"url":"https://blog.gitea.com/release-of-1.26.2/","name":"Gitea v1.26.2 Release Blog Post","tags":["release-notes"]}],"providerMetadata":{"orgId":"88ee5874-cf24-4952-aea0-31affedb7ff2","shortName":"Gitea","dateUpdated":"2026-07-03T20:19:34.133Z"},"credits":[{"lang":"en","value":"ddd","type":"reporter"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"}}],"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"references":[{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-mm7c-rhg6-qr4r","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-07T14:44:56.666791Z","id":"CVE-2026-26231","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-07T16:59:29.212Z"}}]}}