CVE-2026-58416

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)


We have discovered 777 live websites that are affected by CVE-2026-58416.

Run a Free Instant Scan




Affected Software

Product  Gitea
Category Dev Tools
Vulnerable Domains777 live websites (100% of Gitea install base)
Vulnerable Versions
  • from 0 through 1.26.4
Vulnerable Versions Count66 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-280 Improper Handling of Insufficient Permissions or Privileges



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • CassianStarck (reporter)

Website Distribution by Country

Number of websites using CVE-2026-58416
United States192 websites



Germany206 websites
France104 websites
Russia47 websites
Singapore42 websites
China23 websites
Czech Republic18 websites
Netherlands16 websites
GB15 websites
Canada10 websites

Website Distribution by TLD

Number of websites using CVE-2026-58416
.com191 websites
.net78 websites
.org77 websites
.de77 websites
.ru32 websites
.fr27 websites
.eu16 websites
.nl14 websites
.io12 websites
.cz11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-58416

Top websites that are affected by CVE-2026-58416. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.********.com United States***,***
***.*************.org United States***,***
*****.**********.eu Germany***,***
***.*******.net United States***,***
******************.com United States*,***,***
**********.es France*,***,***
****.********.ch Switzerland*,***,***
***.*******.fi Finland*,***,***
***.*********.rip Germany*,***,***
***.************.com France*,***,***
See full domain list

FAQ

CVE-2026-58416 is Improper Handling of Insufficient Permissions or Privileges in Gitea
A total of 777 websites have been identified as vulnerable to CVE-2026-58416, based on global website indexing conducted by WebTechSurvey.
The Gitea is affected by the CVE-2026-58416 vulnerability.
Gitea versions up to and including 1.26.4 are vulnerable to CVE-2026-58416.