CVE-2026-26292
Last modified
CVE-2026-26292 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Gitea | Gitea Open Source Git Server | < 1.25.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-26292?
How severe is CVE-2026-26292?
How do I fix CVE-2026-26292?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26286SillyTavern is a locally installed user interface that allow…8.5
- CVE-2026-26288WebSocket endpoints lack proper authentication mechanisms, e…9.8
- CVE-2026-26289PowerSYSTEM Center REST API endpoint for device account expo…8.4
- CVE-2026-2629A weakness has been identified in jishi node-sonos-http-api …7.3
- CVE-2026-26290The WebSocket backend uses charging station identifiers to u…9.8
- CVE-2026-26291Stored cross-site scripting vulnerability exists in GROWI v7…5.4
- CVE-2026-26295Rejected reason: Not used
- CVE-2026-26296Rejected reason: Not used
- CVE-2026-26297Rejected reason: Not used
- CVE-2026-26298Rejected reason: Not used
- CVE-2026-26299Rejected reason: Not used
- CVE-2026-2630A Command Injection vulnerability exists where an authentica…8.8
Are you affected by CVE-2026-26292?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
