CVE-2026-52815Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpoint at internal/route/api/v1/org_team.go:8 returns all teams for any organization without requiring authentication. The route group at internal/route/api/v1/api.go:380-385 lacks the reqToken() middleware, and the listTeams() handler performs no authentication check, exposing team IDs, names, descriptions, and permission levels to any unauthenticated caller. This vulnerability is fixed in 0.14.3.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-24: 3PoC Mentioned / Linked · 2026-06-24: 1Technical Details · 2026-06-24: 306-24
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-52815 - low 🚨 Gogs < 0.14.3 - Unauthenticated Organization Teams Disclosure > Gogs before version 0.14.3 contains an unauthenticated information disclosure vulnera... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-52815 @pdnuclei #NucleiTemplates #cve

    Post summary

    A new low‑severity CVE‑2026‑52815 has been disclosed, exposing an unauthenticated information disclosure in Gogs versions before 0.14.3. A documentation link is provided, but no exploit code or active usage is reported.

    00020284
    1.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-52815 Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams… https://www.cve.org/CVERecord?id=CVE-2026-52815 ----- Traducción: CVE-2026-52815 Gog… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-52815 as an unauthenticated information disclosure in Gogs prior to v0.14.3, including the affected API path.

    0000047
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-52815 Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams… https://www.cve.org/CVERecord?id=CVE-2026-52815

    Post summary

    The post announces CVE‑2026‑52815, describing an unauthenticated info‑disclosure flaw in Gogs’ API endpoint.

    00000685
    57.7K followersView on X

Explore more