Security Advisory

CVE-2026-28699

8.1
HIGH

Vulnerability Description

Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
Published Date July 3, 2026
Official Source NIST NVD Advisory