CVE-2026-26231: Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo
Any authenticated low-privilege user with read access to a repository can push arbitrary commits directly to that repository, bypassing all write-access checks.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-26231 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →