Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56654

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Privilege Escalation via Access Token Scope Escalation in API

A flaw was found in Gitea. This vulnerability allows an attacker to escalate their privileges by manipulating the scope of an access token within the API. This means an attacker could gain unauthorized access to sensitive functions or data, potentially leading to full control over affected resources.

Отчет

Important: An authenticated attacker with a limited-scope API token in Gitea could escalate their privileges. This is due to a flaw in how Gitea's API processes basic authentication with tokens, allowing the creation of new tokens with elevated scopes beyond the original token's permissions. Red Hat OpenShift Pipelines does not deploy Gitea web servers.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Pipelinesopenshift-pipelines-clientNot affected
OpenShift Pipelinesopenshift-pipelines/pipelines-cli-tkn-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-cli-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-controller-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-pipelines-as-code-watcher-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2515464code.gitea.io/gitea: Gitea: Privilege Escalation via API Access Token Scope Escalation

EPSS

Процентиль: 35%
0.00418
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
26 дней назад

Privilege Escalation via Access Token Scope Escalation in API

CVSS3: 8.8
redos
27 дней назад

Уязвимость gitea

CVSS3: 8.8
redos
27 дней назад

Уязвимость gitea

github
около 2 месяцев назад

Gitea: Privilege Escalation via Access Token Scope Escalation in API

EPSS

Процентиль: 35%
0.00418
Низкий

8.8 High

CVSS3