CVE-2026-52815 Scanner
CVE-2026-52815 Scanner - Information Disclosure vulnerability in Gogs
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
25 days 16 hours
Scan only one
Domain, Subdomain, IPv4
Toolbox
Gogs is a self-hosted Git service, designed to serve as an easily deployable and lightweight version of GitHub for team and individual projects. It supports collaboration by managing git repositories with a friendly user interface, often used by small and medium-sized teams to host their project codes securely. Organizations like startups, educational institutions, and development groups frequently rely on Gogs for version control and collaborative coding. The platform lets users manage repositories, branches, and merge requests within a dedicated and controlled environment. It helps teams streamline their development workflows while maintaining security over codebase access. Gogs is appreciated for its simplicity, ease of installation, and active community support.
The information disclosure vulnerability in Gogs before version 0.14.3 allows unauthenticated attackers to access protected organizational data. The vulnerability is related to the lack of authentication required to access organizational team information. By exploiting this flaw, attackers can retrieve details like team IDs, names, descriptions, and permission levels without logging in. This security gap can lead to exposure of sensitive information about the organization's structure and operations. It particularly affects configurations that do not apply middleware to verify requests. Addressing this vulnerability is crucial for maintaining the confidentiality and integrity of organizational data within hosted Gogs instances.
The technical aspect of this vulnerability arises from the Gogs REST API endpoint `/api/v1/orgs/:orgname/teams`. This endpoint is designed to return team information within an organization but erroneously allows data retrieval without requiring user authentication. Specifically, the vulnerability lies in the absence of the `reqToken()` middleware that enforces authentication. Consequently, unauthenticated users can exploit this endpoint to enumerate all teams in any given organization. This data includes not just public team details but also private or restricted information not meant for public disclosure.
If exploited, this vulnerability can result in the exposure of organizational structures including team membership, roles, and permissions. Attackers could exploit this to map an organization's internal hierarchy and discover privileged administrator or owner teams. This could facilitate further targeted attacks, such as privilege escalation or social engineering, by exposing valuable insights into the organization's operations and personnel. The unauthorized access to sensitive information compromises the confidentiality and integrity of the data maintained within the Gogs system.
REFERENCES