Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Changing an organization team's permission through the API with only the `permission` field did not rebuild the team's per-unit access, and the requested level was not applied as a cap. After an organization owner demoted a team, for example from admin to read, the team's members kept their previous unit permissions, including write access to the team's repositories. The web form was not affected. | |
| Title | Gitea API team demotion not applied to unit permissions | |
| Weaknesses | CWE-272 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-10-06T19:24:26.369Z
Reserved: 2026-10-04T21:59:53.566Z
Link: CVE-2026-103504
No data.
Status : Received
Published: 2026-10-06T20:17:14.487
Modified: 2026-10-06T20:17:14.487
Link: CVE-2026-103504
No data.
OpenCVE Enrichment
No data.
Weaknesses