CVE-2026-27657: Gitea email settings allow changing another user's primary email address
Published Jul 3, 2026
·Updated
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
Affected Software
1 affected component
Gitea Gitea<1.25.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Giteato a version that resolves this vulnerability.Fixed in 1.25.5
Event History
Jul 3, 2026
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27657?
CVE-2026-27657 has a risk rating of 56.
2
How do I fix CVE-2026-27657?
To fix CVE-2026-27657, upgrade to Gitea version 1.25.5 or later.
3
What type of vulnerability is CVE-2026-27657?
CVE-2026-27657 is a privilege escalation vulnerability that allows unauthorized changes to a user's primary email address.
4
Which versions of Gitea are affected by CVE-2026-27657?
Versions of Gitea prior to 1.25.5 are affected by CVE-2026-27657.
5
Who is impacted by CVE-2026-27657?
Users of Gitea prior to version 1.25.5 are at risk from CVE-2026-27657 due to the ability to change another user's primary email address.