Skip to main content
HIGH

CVE-2026-103504

Gitea API team demotion not applied to unit permissions

CVSS v3

8.1

HIGH

EPSS Score

—

exploit probability

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Published
2026-10-06
Last Modified
2026-10-07

Frequently asked questions

What is CVE-2026-103504?

Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.

Is CVE-2026-103504 actively exploited?

Active exploitation of CVE-2026-103504 has not been confirmed.

What is the CVSS score for CVE-2026-103504?

CVE-2026-103504 has a CVSS v3 base score of 8.1 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N.

Is CVE-2026-103504 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key