Skip to content

Restricted users can enumerate limited-visibility organizations via the user org-list API (authorization bypass)

Low
bircni published GHSA-w4wc-g858-3672 Aug 29, 2026

Package

gomod code.gitea.io/gitea (Go)

Affected versions

<= 1.27.2

Patched versions

1.27.3

Description

Summary

A restricted account can enumerate Limited-visibility organizations and their name, description and avatar by listing the public organization memberships of a known user through GET /api/v1/users/{username}/orgs.

Details

The helper that decides which organization visibilities to include for the viewer returns "Limited" for any signed-in, non-admin, non-self viewer without excluding restricted accounts, so the response admits both public and limited organizations. The single-organization endpoint GET /api/v1/orgs/{org} correctly returns 404 to a restricted viewer for a limited organization; the list path uses a different, unrestricted helper.

Impact

Authorization boundary / confidentiality. A restricted account, which by policy may reach only public content, can discover Limited-visibility organizations and their metadata by walking the public memberships of known users.

Affected versions

Gitea <= 1.27.2.

Patches

Fixed in Gitea 1.27.3 (#39047, #39058).

Workarounds

None. Upgrade to 1.27.3.

Severity

Low

CVE ID

CVE-2026-66853

Weaknesses

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. Learn more on MITRE.

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. Learn more on MITRE.

Credits