CVE-2026-27657
published 2026-07-03CVE-2026-27657: Gitea versions before 1.25.5 allow a user to change another user's primary email address.
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.34%
27.8th percentile
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitea | gitea_open_source_git_server | < 1.25.5 | 1.25.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Gitea up to 1.25.4 Email Address authorization
vuldb·2026-07-04
CVE-2026-27657 [LOW] Gitea up to 1.25.4 Email Address authorization
A vulnerability categorized as problematic has been discovered in Gitea up to 1.25.4. The affected element is an unknown function of the component Email Address Handler. The manipulation results in authorization bypass.
This vulnerability is reported as CVE-2026-27657. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
ghsa_unreviewed·2026-07-03
CVE-2026-27657 CWE-639 Gitea versions before 1.25.5 allow a user to change another user's primary email address.
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-03
Published