PatchSiren cyber security CVE debrief
CVE-2026-86684 Gitea CVE debrief
The Gitea push mirror API incorrectly checks repository owner permissions instead of requesting user permissions. This allows a repository administrator to add a push mirror to a local path when the repository owner has that permission. Consequently, refs could be pushed into an existing Git repository at that path, potentially leading to unauthorized modifications. Gitea instance administrators should verify configurations and repository permissions, focusing on instances with `[security] IMPORT_LOCAL_PATHS = true`.
- Vendor
- Gitea
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-07
Who should care
Gitea instance administrators, repository administrators, developers using Gitea, and security teams responsible for vulnerability management should be aware of this issue. They should assess their exposure, especially if `[security] IMPORT_LOCAL_PATHS = true` is enabled, and take appropriate remediation steps to prevent unauthorized modifications.
Why it matters
Gitea push mirror API vulnerability allows repository administrators to add push mirrors to local paths, potentially pushing refs into existing Git repositories, requiring verification and remediation.
- Potential unauthorized pushing of refs into existing Git repositories.
- Possible exploitation by repository administrators with specific permissions.
- Requires verification of Gitea instance configuration and repository permissions.
- Remediation priority for instances with `[security] IMPORT_LOCAL_PATHS = true`.
Technical summary
The Gitea push mirror API checks repository owner permissions instead of requesting user permissions. This flaw allows a repository administrator to add a push mirror to a local path when the repository owner has that permission, potentially pushing refs into an existing Git repository at that path. The vulnerability is particularly concerning for Gitea instances with `[security] IMPORT_LOCAL_PATHS = true` enabled, as it could lead to unauthorized modifications of Git repositories on the server's file system. Instance administrators and developers should assess exposure and prioritize remediation.
Defensive priority
Repository administrators and Gitea instance maintainers should verify exposure and prioritize remediation.
Recommended defensive actions
- Verify Gitea instance configuration and repository permissions.
- Update to version 28.1.0 or later.
- Review and restrict push mirror configurations.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description and affected versions. Evidence is limited to public sources and may not cover all potential impacts or affected configurations. Defenders should verify Gitea instance configurations, especially where `[security] IMPORT_LOCAL_PATHS = true`, and review repository permissions for potential exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86684 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86684
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86684 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86684
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Gitea push mirror local path check uses the repository owner
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/86xxx/CVE-2026-86684.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/security/advisories/GHSA-7v5j-mph8-9w6g
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39501
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/pull/39507
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://blog.gitea.com/release-of-28.1.0/
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/go-gitea/gitea/releases/tag/v28.1.0
Supplemental source - release-notes
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.