Description
When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the named recipient kept persistent read access to the private repository, including its code, issues, pull requests and wiki, and could clone it. The repository owner was not notified. Transfer-granted access is now removed while collaborations that existed before the transfer are preserved.
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized access to private repository contents
Action: Update to v28.0.0
AI Analysis

Impact

During a transfer of a private repository to another user, Gitea grants temporary read access to the recipient as a collaborator so they can inspect the repository. When the transfer is later rejected or cancelled, the recipient’s collaboration is not revoked, allowing them to retain persistent read access to all private data, including code, issues, pull requests and the wiki. The repository owner receives no notification of this continued access, enabling the recipient to clone the entire repository. The vulnerability allows an attacker to obtain confidential information from a private repository that should be inaccessible after a transfer rejection.

Affected Systems

The issue affects Gitea Gitea installations running versions prior to the release of 28.0.0. The 28.0.0 update removes the retained read access while preserving any previous collaborations that existed before the transfer.

Risk and Exploitability

The vulnerability is exploitable through the normal web interface used to transfer repositories, so an attacker only needs to be the target of a transfer request or have permission to initiate it. Although the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the impact of persistent read access to a private repository is substantial, potentially exposing sensitive code and project information. The lack of an EPSS figure suggests that exploitation may not be widespread at this time, but the absence of a KEV listing does not reduce the seriousness of the unauthorized access risk.

Generated by OpenCVE AI on October 6, 2026 at 23:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Gitea patch by upgrading to version 28.0.0
  • After upgrading, verify that any pending or rejected transfer recipients no longer have collaborator status
  • If an immediate upgrade is not possible, remove the collaborator role for the rejected transfer recipient manually while continuing to monitor for unauthorized access

Generated by OpenCVE AI on October 6, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the named recipient kept persistent read access to the private repository, including its code, issues, pull requests and wiki, and could clone it. The repository owner was not notified. Transfer-granted access is now removed while collaborations that existed before the transfer are preserved.
Title Gitea private repository access retained after rejected transfer
Weaknesses CWE-672
CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-10-06T19:25:38.737Z

Reserved: 2026-10-04T21:59:53.552Z

Link: CVE-2026-96589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:35.710

Modified: 2026-10-06T20:17:35.710

Link: CVE-2026-96589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T23:30:08Z

Weaknesses
  • CWE-672

    Operation on a Resource after Expiration or Release

  • CWE-863

    Incorrect Authorization