PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104632 Gitea CVE debrief

Gitea fork workflow approval bypass through cancel and rerun. The rerun path only required a run to be finished and built the new attempt's jobs without considering the pending approval, so when a user with Actions write access cancelled a run that was awaiting approval and then re-ran it, the new jobs were created as waiting rather than blocked while the run still recorded that approval was required.

Vendor
Gitea
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-07
Advisory published
2026-10-06
Advisory updated
2026-10-07

Who should care

Defenders responsible for Gitea deployments with Actions enabled should assess exposure and review workflow configurations to ensure proper approval controls are in place. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify exposure and implement mitigations to prevent unauthorized workflow execution.

Why it matters

Defenders should prioritize verifying exposure in Gitea deployments with Actions enabled and reviewing workflow configurations to ensure proper approval controls are in place. The vulnerability allows users with Actions write access to bypass approval controls by cancelling and re-running a workflow run, potentially allowing workflow code from a fork pull request head to run on the repository's runners without explicit approval. Evidence is limited to the CVE record and source item, and further verification is needed to determine the full scope of affected versions and remediation steps.

  • Potential unauthorized workflow execution without approval
  • Possible exposure of repository runners to unapproved workflow code

Technical summary

The Gitea fork workflow approval bypass vulnerability allows users with Actions write access to bypass approval controls by cancelling and re-running a workflow run. This could potentially allow workflow code from a fork pull request head to run on the repository's runners without explicit approval. The vulnerability affects Gitea deployments with Actions enabled, and defenders should prioritize verifying exposure and reviewing workflow configurations to ensure proper approval controls are in place. Evidence is limited to the CVE record and source item, and further verification is needed to determine the full scope of affected versions and remediation steps.

Defensive priority

Defenders should prioritize verifying exposure in Gitea deployments with Actions enabled and reviewing workflow configurations to ensure proper approval controls are in place.

Recommended defensive actions

  • Verify Gitea deployments with Actions enabled to assess exposure
  • Review workflow configurations to ensure proper approval controls are in place
  • Consider upgrading to a version beyond 1.27.3 if possible
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description and affected versions. However, the corpus does not establish versions beyond 1.27.3 or provide specific remediation steps beyond upgrading.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104632 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104632

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104632 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104632

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Gitea fork workflow approval bypass through cancel and rerun

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104632.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-pvjf-7jrm-6w9g

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/pull/39399

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://blog.gitea.com/release-of-28.0.0/

    Supplemental source - release-notes

  • Source reference

    Unverified legacy reference

    URL: https://github.com/go-gitea/gitea/releases/tag/v28.0.0

    Supplemental source - release-notes

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.