CVE-2026-86684
Description
A flaw was found in Gitea. An improper authorization check in the push mirror API allows an authenticated repository administrator to bypass local file system access restrictions. When a repository owner has permission to use local paths, an administrator lacking that privilege can configure a push mirror pointing to a local path on the server. Gitea then pushes repository data to that target using the server process's privileges, which may lead to unauthorized file modification and privilege escalation.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity
A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.