Medium [CVE-2026-58438] Unauthorized tampering and commenting on private repositories via insecure direct object reference
This medium-severity Red Hat Linux advisory covers CVE-2026-58438 affecting OpenShift Pipelines.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access A flaw was found in Gitea. This vulnerability, identified as an Insecure Direct Object Reference (IDOR), exists within the issue-dependency removal function.
A remote attacker with write access to issues in one repository can exploit this flaw to remove a dependency link to an issue in a private repository they are not authorized to access.
This allows the attacker to tamper with issue-tracking states and inject comments into private repositories, leading to unauthorized write operations across private repository boundaries.
Due to insufficient authorization checks, a remote user with issue-write access in one repository can manipulate dependency relations pointing to an issue in a separate, restricted private repository.
An attacker can exploit this IDOR flaw by targeting known issue IDs to remove dependency links and inject unauthorized system comments into private repositories beyond their permitted access scope, compromising cross-repository data integrity. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).
Weakness: CWE-639. Affected Red Hat products: OpenShift Pipelines.
Red Hat does not currently list a fixing RHSA for this CVE.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- To mitigate this issue, restrict write access to repository issues to trusted users, or temporarily disable issue tracking on affected repositories until a patch is applied.
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.