CVE-2026-103504

Published: Ott 06, 2026 Last Modified: Ott 06, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.

272

Least Privilege Violation

Incomplete
Common Consequences
Security Scopes Affected:
Access Control Confidentiality
Potential Impacts:
Gain Privileges Or Assume Identity Read Application Data Read Files Or Directories
Applicable Platforms
All platforms may be affected
View CWE Details
https://blog.gitea.com/release-of-28.0.0/
https://github.com/go-gitea/gitea/pull/38938
https://github.com/go-gitea/gitea/releases/tag/v28.0.0
https://github.com/go-gitea/gitea/security/advisories/GHSA-x8c3-3rp8-2j46