Security Advisory
CVE-2026-27761
4.3
MEDIUM
Vulnerability Description
Gitea versions up to and including 1.26.2 allow repository RSS and Atom feed endpoints to bypass API access token scope checks, exposing private repository commit data to tokens without the required repository scope.
Published Date
July 3, 2026
Official Source
NIST NVD Advisory