Sploitus

CVE-2026-28699

2 known exploits for CVE-2026-28699

Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.

Affected products
Gitea, Red Os
CVSS 3.1
8.1 HIGH
EPSS
0.6% (44th percentile)
Weakness
CWE-863, CWE-284
NVD status
Deferred
Published
2026-07-03
CVE-2026-28699 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-28699

Proof-of-concept code and exploit modules indexed by Sploitus