Security Digest: June 17, 2026 - 5 Critical Vulnerabilities

Five newly disclosed vulnerabilities affect widely used developer and hosting tools, with the most urgent enabling unauthenticated remote command execution in rclone and repository takeover in Gitea. Two additional Gitea flaws let attackers bypass token scope controls, while a Gogs path traversal bug can be used to trigger denial of service and write outside the intended directory.

· 8 min read

June 17, 2026 Security Alert: Five High-Risk Flaws Demand Immediate Action

Executive Summary

Five newly disclosed vulnerabilities affect widely used developer and hosting tools, with the most urgent enabling unauthenticated remote command execution in rclone and repository takeover in Gitea. Two additional Gitea flaws let attackers bypass token scope controls, while a Gogs path traversal bug can be used to trigger denial of service and write outside the intended directory.

Action required now: patch exposed systems immediately, restrict remote-control and Git service access, and verify whether any affected services are reachable from the public internet or from untrusted users.

Critical Vulnerabilities

CVE-2026-49980: rclone rc serve unauthenticated command execution

  • Impact: A network attacker who can reach the rclone RC listener can execute commands as the rclone process user. The same flaw can also expose local files and mutate global rclone settings.
  • Affected Systems: github.com/rclone/rclone, versions 1.55.0 and later when --rc or rclone rcd is enabled with --rc-serve and no RC authentication.
  • Immediate Action: Upgrade to rclone 1.74.3 or the forthcoming 1.75.0. If you cannot patch immediately, add RC authentication and confirm the listener is not exposed beyond localhost.
  • Mitigation: Use --rc-user/--rc-pass or --rc-htpasswd, or disable --rc-serve entirely if file serving is not required.

CVE-2026-26231: Gitea maintainer-edit bypass enables unauthorized pushes

  • Impact: Any logged-in user with read access can push arbitrary commits into repositories they should not be able to modify, including public repositories. This is effectively a full repository compromise risk.
  • Affected Systems: code.gitea.io/gitea, affected releases exposing the reverse-fork PR and maintainer-edit flow described in the advisory.
  • Immediate Action: Treat all repositories on affected instances as at risk. Restrict who can create forks and PRs, and patch as soon as a fixed release is available from the vendor.
  • Mitigation: Add a write-access check at PR creation and strengthen push-time validation so maintainer-edit is never trusted based only on the fork/base repository.

CVE-2026-52797: Gogs preview path traversal leads to arbitrary file write and DoS

  • Impact: An authenticated user can abuse the file preview path to write comparison output to an arbitrary path, potentially corrupting database or configuration files and causing denial of service.
  • Affected Systems: gogs.io/gogs, specifically the repository editor preview path handling in affected builds.
  • Immediate Action: Assume authenticated users may be able to target files outside the intended repository path. Disable or restrict preview features if you cannot patch immediately.
  • Mitigation: Replace unsafe path handling with pathutil.Clean and ensure the filtered, normalized path is the only value passed into diff generation.

CVE-2026-28699: Gitea OAuth2 scope bypass via Basic authentication

  • Impact: A token limited to read-only OAuth2 access can perform write actions when submitted through HTTP Basic auth, including profile changes, email additions, repository creation, and repository deletion.
  • Affected Systems: code.gitea.io/gitea, OAuth2-enabled instances that accept access tokens over Basic authentication.
  • Immediate Action: Review OAuth2 apps and tokens now. If your instance supports token-based Basic auth, assume scope enforcement may be bypassed until patched.
  • Mitigation: Ensure OAuth2 access tokens accepted via Basic auth are assigned the same scope context as Bearer tokens, so scope checks cannot be skipped.

CVE-2026-28744: Gitea Git Smart HTTP scope check bypass via Bearer tokens

  • Impact: A PAT or OAuth2 token sent as a Bearer credential can bypass repository scope checks during Git Smart HTTP, allowing unauthorized clone/fetch access and potentially unauthorized push attempts.
  • Affected Systems: code.gitea.io/gitea, versions where Git Smart HTTP accepts Bearer auth but enforces repository scopes only for Basic auth.
  • Immediate Action: Treat Bearer-token access to Git over HTTP as unsafe until patched. Restrict Git Smart HTTP exposure if possible and audit for unexpected repository access.
  • Mitigation: Enforce repository scope checks regardless of auth transport method; do not gate scope validation on ctx.IsBasicAuth.

What to Do Now

  1. Patch exposed services first: rclone to 1.74.3; Gitea and Gogs to vendor-fixed releases as soon as available.
  2. Lock down access: remove public exposure of RC listeners, Git admin interfaces, and any service that allows unauthenticated or weakly authenticated access.
  3. Rotate credentials: revoke and reissue tokens, OAuth2 grants, and service credentials used on affected systems.
  4. Audit activity: look for unexpected pushes, new commits, repository changes, token misuse, and anomalous RC requests.
  5. Verify configuration: confirm RC authentication is enabled on rclone, and confirm Gitea/Gogs instances are not relying on scope enforcement paths that can be bypassed.

Verification Steps

  • Check rclone deployments for --rc-serve and any listener reachable beyond localhost.
  • Review Gitea logs for suspicious PR creation patterns, especially reverse-fork PRs with maintainer edit enabled.
  • Search for OAuth2 tokens used via Basic auth and Bearer-auth Git requests that accessed private repositories unexpectedly.
  • Inspect Gogs preview endpoints for requests containing unusual path values or output redirection-like parameters.

Monitoring Recommendations

  • Alert on new commits to sensitive branches outside normal maintainer workflows.
  • Alert on RC requests to rclone from non-local addresses or from browser-originated traffic.
  • Monitor for repository creation, deletion, and email/profile changes tied to OAuth2 tokens.
  • Watch for database, config, or file integrity changes on Gogs hosts.

Related Resources

  • Internal: A follow-up analysis post on rclone RC exposure and Gitea token-scope bypasses is recommended; not yet published.
  • Official vendor advisories: rclone advisory for CVE-2026-49980; Gitea advisory for CVE-2026-26231, CVE-2026-28699, and CVE-2026-28744; Gogs advisory for CVE-2026-52797.

Keep reading