CVE-2026-103504
CVE-2026-103504 is a security vulnerability that is still awaiting full analysis and scoring. The underlying weakness is classified as CWE-272.
Key facts
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-272
- Published:
- Last modified:
Description
Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.
Frequently asked questions
- What is CVE-2026-103504?
- Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.
- Is CVE-2026-103504 being actively exploited?
- It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
- How do I fix CVE-2026-103504?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-103504 published?
- CVE-2026-103504 was published on 2026-10-06.
References
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/pull/38938
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
- https://github.com/go-gitea/gitea/security/advisories/GHSA-x8c3-3rp8-2j46
Other CWE-272 vulnerabilities
- CVE-2025-59106 — High (CVSS 8.8): The binary serving the web server and executing basically all actions launched from the Web UI is running with root…
- CVE-2025-7722 — High (CVSS 8.8): The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including,…
- CVE-2024-28824 — High (CVSS 8.8): Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk…
- CVE-2024-35204 — High (CVSS 8.4): Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus…
- CVE-2025-47809 — High (CVSS 8.2): Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or…
- CVE-2024-0638 — High (CVSS 8.2): Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk…