A critical Gitea authorization bypass tracked as CVE-2026-58443 allows a public-only access token with write:repository scope to push commits into a private repository under specific pull request conditions. The flaw affects Gitea releases up to and including v1.26.4 and was fixed in v1.27.0. Researchers said the issue lies in the pull request update endpoint, where Gitea checks the token’s public-only restriction against the public base repository but fails to enforce that restriction again when operating on the private head repository.
The bug can be abused to perform unauthorized server-side merges or rebases into a private pull request head branch, and those writes may also trigger Gitea Actions workflows on the private repository if Actions is enabled. Public reporting included a technical analysis and a working proof-of-concept, though no confirmed in-the-wild exploitation was cited. Administrators were urged to upgrade to v1.27.0, audit and rotate or revoke public-only tokens with write permissions, review public-to-private pull request relationships, and inspect recent private repository pushes and Actions logs for suspicious activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting disclosed CVE-2026-58443 as a critical authorization bypass in Gitea, explaining that public-only tokens with write:repository scope could indirectly write to private pull request head branches and trigger private workflows when Actions is enabled. The disclosure also reiterated upgrade and token-audit recommendations for administrators.
Gitea addressed CVE-2026-58443 in v1.27.0. The vulnerability affected all releases up to and including v1.26.4 and allowed a public-only token to write to a private repository under specific pull request conditions.
Researchers published technical details and working proof-of-concept code for CVE-2026-58443, showing how the pull request update endpoint could be abused to push commits into a private repository and potentially trigger Gitea Actions workflows. The available reporting noted no confirmed in-the-wild exploitation in the cited content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.