CVE-2026-26231EPSS p21.6%

CVE-2026-26231CVE-2026-26231

Description

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.

Scoring

CVSS 8.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
EPSS0.29% probability of exploitation · percentile 21.6% · 2026-08-17T12:03:47Z
Last modified2026-07-07
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.