Description
CVE-2026-28699 — Gitea OAuth2 Scope Bypass via HTTP Basic Auth Self-contained lab + writeup for CVE-2026-28699: a Gitea OAuth2 access token scoped to only read:user can perform full write actions just by being sent as Authorization: Basic...
Basic Information
ID
A80B7830-0196-594A-AA8C-1EF928459222
Published
Jun 11, 2026 at 02:23
Modified
Jun 11, 2026 at 02:29