CVE-2026-52804EPSS p40.6%

CVE-2026-52804CVE-2026-52804

Description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their privileges to owner-level access by exploiting an off-by-one error in the ChangeCollaborationAccessMode function. This vulnerability is fixed in 0.14.3.

Scoring

EPSS0.50% probability of exploitation · percentile 40.6% · 2026-10-05T12:00:23Z
Last modified2026-06-26
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.