CVE-2026-103504: Gitea
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.
Affected products
- Gitea Gitea: up to and including 1.27.3
Published 2026-10-06. Last modified 2026-10-07.