CVE-2026-104632
Last modified
CVE-2026-104632 is a vulnerability of currently unknown severity. Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run. The rerun path only required a run to be finished and built the new attempt's jobs without considering the pending approval, so when a user with Actions write access cancelled a run that was awaiting approval and then re-ran it, the new jobs were created as waiting rather than blocked while the run still recorded that approval was required.
Description
Gitea Actions blocks the jobs of workflow runs from first-time fork pull request contributors until a maintainer approves the run. The rerun path only required a run to be finished and built the new attempt's jobs without considering the pending approval, so when a user with Actions write access cancelled a run that was awaiting approval and then re-ran it, the new jobs were created as waiting rather than blocked while the run still recorded that approval was required. Cancelling and re-running stale fork checks is a routine action that does not involve the approval control, so where Actions is enabled and a matching runner is registered, workflow code taken from the fork pull request head could run on the repository's runners without an explicit approval.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Gitea | Gitea | <= 1.27.3 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-104632?
How severe is CVE-2026-104632?
How do I fix CVE-2026-104632?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104611A vulnerability was detected in Tenda AC9 15.03.02.13. Affec…9.1
- CVE-2026-104612A vulnerability was found in SourceCodester Student Result M…4.3
- CVE-2026-104613A vulnerability was determined in CodeAstro Simple Pharmacy …6.3
- CVE-2026-104614A vulnerability was identified in CodeAstro Simple Pharmacy …6.3
- CVE-2026-104625A security flaw has been discovered in CodeAstro Simple Loan…6.3
- CVE-2026-104626A user who can open a fork pull request can place workflow c…
- CVE-2026-104633When migrating a repository from another Gitea instance, Git…
- CVE-2026-104636Gitea validated the initial remote URL for push mirrors, wik…
- CVE-2026-104637A weakness has been identified in onetwothreeneth HospitalMa…7.3
- CVE-2026-104638A security vulnerability has been detected in onetwothreenet…5.3
- CVE-2026-104651The Yaad Sarig Payment Gateway For WC WordPress plugin befor…4.3
- CVE-2026-104652The Envira Gallery WordPress plugin before 1.16.1 does not …6.8
Are you affected by CVE-2026-104632?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
