CVE-2026-58429
Description
AI Translation Available
Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
284
Improper Access Control
IncompleteCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Varies By Context
Applicable Platforms
Technologies:
Not Technology-Specific, ICS/OT, Web Based
1259
Improper Restriction of Security Token Assignment
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Access Control
Potential Impacts:
Modify Files Or Directories
Execute Unauthorized Code Or Commands
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Modify Memory
Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies:
Processor Hardware, Not Technology-Specific, System on Chip
https://blog.gitea.com/gitea-1.27.0-is-released/
https://github.com/go-gitea/gitea/releases/tag/v1.27.0
https://github.com/go-gitea/gitea/security/advisories/GHSA-fq2p-5p22-8g6j