CVE-2026-52815 Scanner

CVE-2026-52815 Scanner - Information Disclosure vulnerability in Gogs

Short Info


Level

Medium

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

25 days 16 hours

Scan only one

Domain, Subdomain, IPv4

Toolbox

Gogs is a self-hosted Git service, designed to serve as an easily deployable and lightweight version of GitHub for team and individual projects. It supports collaboration by managing git repositories with a friendly user interface, often used by small and medium-sized teams to host their project codes securely. Organizations like startups, educational institutions, and development groups frequently rely on Gogs for version control and collaborative coding. The platform lets users manage repositories, branches, and merge requests within a dedicated and controlled environment. It helps teams streamline their development workflows while maintaining security over codebase access. Gogs is appreciated for its simplicity, ease of installation, and active community support.

The information disclosure vulnerability in Gogs before version 0.14.3 allows unauthenticated attackers to access protected organizational data. The vulnerability is related to the lack of authentication required to access organizational team information. By exploiting this flaw, attackers can retrieve details like team IDs, names, descriptions, and permission levels without logging in. This security gap can lead to exposure of sensitive information about the organization's structure and operations. It particularly affects configurations that do not apply middleware to verify requests. Addressing this vulnerability is crucial for maintaining the confidentiality and integrity of organizational data within hosted Gogs instances.

The technical aspect of this vulnerability arises from the Gogs REST API endpoint `/api/v1/orgs/:orgname/teams`. This endpoint is designed to return team information within an organization but erroneously allows data retrieval without requiring user authentication. Specifically, the vulnerability lies in the absence of the `reqToken()` middleware that enforces authentication. Consequently, unauthenticated users can exploit this endpoint to enumerate all teams in any given organization. This data includes not just public team details but also private or restricted information not meant for public disclosure.

If exploited, this vulnerability can result in the exposure of organizational structures including team membership, roles, and permissions. Attackers could exploit this to map an organization's internal hierarchy and discover privileged administrator or owner teams. This could facilitate further targeted attacks, such as privilege escalation or social engineering, by exposing valuable insights into the organization's operations and personnel. The unauthorized access to sensitive information compromises the confidentiality and integrity of the data maintained within the Gogs system.

REFERENCES

Get started to protecting your digital assets