Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 07 Oct 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitea
Gitea gitea |
|
| Vendors & Products |
Gitea
Gitea gitea |
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When a private repository is transferred to a user who lacks access, Gitea grants that recipient temporary read access as a collaborator so they can review the repository. Rejecting or cancelling the transfer did not revoke this collaboration, so the named recipient kept persistent read access to the private repository, including its code, issues, pull requests and wiki, and could clone it. The repository owner was not notified. Transfer-granted access is now removed while collaborations that existed before the transfer are preserved. | |
| Title | Gitea private repository access retained after rejected transfer | |
| Weaknesses | CWE-672 CWE-863 |
|
| References |
|
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-07T14:30:41.814Z
Reserved: 2026-10-04T21:59:53.552Z
Link: CVE-2026-96589
Updated: 2026-10-07T14:29:10.008Z
Status : Awaiting Analysis
Published: 2026-10-06T20:17:35.710
Modified: 2026-10-07T15:17:59.773
Link: CVE-2026-96589
No data.
OpenCVE Enrichment
Updated: 2026-10-07T00:30:08Z