Sploitus

CVE-2026-27775

No indexed exploits for CVE-2026-27775 yet

Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.

Affected products
Gitea
CVSS 3.1
8.8 HIGH
EPSS
0.6% (44th percentile)
Weakness
CWE-863
NVD status
Deferred
Published
2026-07-03
CVE-2026-27775 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-27775 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-27775 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.