Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth
golang oauth2 authentication exploit poc gitea bug-bounty vulnerability cve access-control http-basic-auth security-research authorization-bypass cve-2026-28699 scope-bypass
-
Updated
Jun 11, 2026 - Python