Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
gitea-CVE-2026-28699 — Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth | Kitploit
Tools/GitHubGitHub/alardiians/gitea-cve-2026-28699
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingLearning & EducationLabs & Practice
GitHubalardiians/gitea-cve-2026-28699

gitea-CVE-2026-28699

Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth

View Repository
111527 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-28699: Gitea OAuth2 Scope Bypass via HTTP Basic Auth

A Gitea OAuth2 access token scoped to only read:user can perform full write actions when it is sent as Authorization: Basic base64(<token>:x-oauth-basic) instead of as a Bearer token. The scope check is skipped for any token presented over Basic auth.

Affected: <= 1.26.1. Fixed in 1.26.2. Advisory: GHSA-9r5x-wg6m-x2rc. CWE-863. Severity High.

Full writeup: WRITEUP.md

Quickstart

pip install -r requirements.txt   # requests
python fetch_binaries.py          # pulls vulnerable 1.26.1 + patched 1.26.2 for your OS
python poc.py 1.26.1              # vulnerable: Basic-auth write succeeds (scope bypassed)
python poc.py 1.26.2              # patched: Basic-auth write blocked (403)

poc.py stands up a throwaway Gitea on SQLite in the system temp dir, runs the OAuth2 authorization-code flow to mint a read:user-only token, then calls a write endpoint over both Bearer and Basic and prints the verdict. Set POC_DEBUG=1 to see the auth-flow steps.

Expected output

Vulnerable 1.26.1:

[Bearer] PATCH /api/v1/user/settings -> HTTP 403   (blocked)
[Basic ] PATCH /api/v1/user/settings -> HTTP 200   (ALLOWED -- scope BYPASSED)
>>> VULNERABLE: read:user token performed a write via Basic auth.

Patched 1.26.2:

[Bearer] PATCH /api/v1/user/settings -> HTTP 403   (blocked)
[Basic ] PATCH /api/v1/user/settings -> HTTP 403   (blocked)
>>> PATCHED: scope enforced on both Bearer and Basic.

Root cause in one table

Auth presentationIsApiTokenApiTokenScopescope enforced?
OAuth2 token via Bearertruesetyes
OAuth2 token via Basictruemissingno (fails open)
Personal access tokentruesetyes

services/auth/basic.go set IsApiToken but not ApiTokenScope for OAuth2 tokens. The tokenRequiresScopes middleware returns early when the scope is absent, so nothing is checked. The 1.26.2 fix adds the missing store.GetData()["ApiTokenScope"] = accessTokenScope.

Files

FilePurpose
WRITEUP.mdRoot-cause analysis, impact, remediation, detection
fetch_binaries.pyDownloads the 1.26.1 / 1.26.2 binaries for your OS/arch
poc.pyProvisions Gitea, mints a read:user token, tests Bearer vs Basic
requirements.txtrequests

Authorised use only

For education and authorised security testing: your own lab, CTF and HTB boxes, in-scope bug bounty targets. The PoC runs its own disposable Gitea, so point it at nothing you don't own.

Download Tool