CVE-2026-20904Improper Access Control in Gitea

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 97.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 22
Latest updateFeb 2

Description

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Patches

🔴Vulnerability Details

3
OSV
Gitea does not properly validate ownership when toggling OpenID URI visibility in code.gitea.io/gitea2026-02-02
OSV
Gitea does not properly validate ownership when toggling OpenID URI visibility2026-01-23
GHSA
Gitea does not properly validate ownership when toggling OpenID URI visibility2026-01-23

📋Vendor Advisories

1
Red Hat
gitea: Gitea: Broken access control in OpenID visibility toggle enables cross-user visibility changes2026-01-22

🕵️Threat Intelligence

1
Wiz
CVE-2026-20904 Impact, Exploitability, and Mitigation Steps | Wiz