Security Advisory
CVE-2026-28699
8.1
HIGH
Vulnerability Description
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
Published Date
July 3, 2026
Official Source
NIST NVD Advisory