CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-52815

mediumcovered by 1 sourcefirst seen 2026-06-23
Summary Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpoint at internal/route/api/v1/org_team.go:8 returns all teams for any organization without requiring authentication. The route group at internal/route/api/v1/api.go:380-385 lacks the reqToken() middleware, and the listTeams() handler performs no authentication check, exposing team IDs, names, descriptions, and permission levels to any unauthenticated caller. Affected Versions Gogs (all current versions) Vulnerability Details Root Cause: Missing reqToken() middleware on org teams route group internal/route/api/v1/api.go lines 380-385: // Org teams route group — no reqToken() middleware m.Group("/:orgname", func() { m.Get("/teams", org.ListTeams) // No auth required }, orgAssignment(true)) The orgAssignment(true) middleware only loads the organization object — it performs no authentication. The listTeams() handler at org_team.go:8 returns all teams unconditionally: func ListTeams(c *context.APIContext) { org := c.Org.Organization teams, err := database.GetTeamsByOrgID(org.ID) // Returns all teams — no c.IsLogged check, no permission check } Compare with other org endpoints that correctly require authentication: m.Group("/orgs/:orgname", func() { // ... other endpoints ... }, reqToken(), orgAssignment(true, true)) // reqToken() enforces auth Attack Chain - Attacker sends GET /api/v1/orgs/target-org/teams with no authentication - orgAssignment(true) loads the organization but does not check auth - ListTeams() queries all teams and returns them - Response includes team IDs, names, descriptions, and permission levels (read/write/admin/owner) Proof of Concept List all teams in an organization — no authentication needed curl -s "http://TARGET:3000/api/v1/orgs/myorg/teams" | python3 -m json.tool Expected: 200 OK with full team list [ { "id": 1, "name": "Owners", "description": "Admin team", "permission": "owner" }, { "id": 2, "name": "backend-devs

⚡ Watch CVE-2026-52815

Get an email if CVE-2026-52815 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-52815

CVE.org record

Embed the live status

CVE-2026-52815 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-52815 status](https://www.csirts.com/badge/CVE-2026-52815)](https://www.csirts.com/cve/CVE-2026-52815)