PatchSiren cyber security CVE debrief
CVE-2026-104632 Gitea CVE debrief
Gitea fork workflow approval bypass through cancel and rerun. The rerun path only required a run to be finished and built the new attempt's jobs without considering the pending approval, so when a user with Actions write access cancelled a run that was awaiting approval and then re-ran it, the new jobs were created as waiting rather than blocked while the run still recorded that approval was required.
- Vendor
- Gitea
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Gitea deployments with Actions enabled should assess exposure and review workflow configurations to ensure proper approval controls are in place. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify exposure and implement mitigations to prevent unauthorized workflow execution.
Why it matters
Defenders should prioritize verifying exposure in Gitea deployments with Actions enabled and reviewing workflow configurations to ensure proper approval controls are in place. The vulnerability allows users with Actions write access to bypass approval controls by cancelling and re-running a workflow run, potentially allowing workflow code from a fork pull request head to run on the repository's runners without explicit approval. Evidence is limited to the CVE record and source item, and further verification is needed to determine the full scope of affected versions and remediation steps.
- Potential unauthorized workflow execution without approval
- Possible exposure of repository runners to unapproved workflow code
Technical summary
The Gitea fork workflow approval bypass vulnerability allows users with Actions write access to bypass approval controls by cancelling and re-running a workflow run. This could potentially allow workflow code from a fork pull request head to run on the repository's runners without explicit approval. The vulnerability affects Gitea deployments with Actions enabled, and defenders should prioritize verifying exposure and reviewing workflow configurations to ensure proper approval controls are in place. Evidence is limited to the CVE record and source item, and further verification is needed to determine the full scope of affected versions and remediation steps.
Defensive priority
Defenders should prioritize verifying exposure in Gitea deployments with Actions enabled and reviewing workflow configurations to ensure proper approval controls are in place.
Recommended defensive actions
- Verify Gitea deployments with Actions enabled to assess exposure
- Review workflow configurations to ensure proper approval controls are in place
- Consider upgrading to a version beyond 1.27.3 if possible
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description and affected versions. However, the corpus does not establish versions beyond 1.27.3 or provide specific remediation steps beyond upgrading.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104632 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104632
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104632 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104632
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Gitea fork workflow approval bypass through cancel and rerun
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104632.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-pvjf-7jrm-6w9g
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39399
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://blog.gitea.com/release-of-28.0.0/
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Supplemental source - release-notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.