CVE-2026-20750

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*

History

27 Jun 2026, 05:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/security/cve/CVE-2026-20750 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2432216 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-20750.json -

17 Jun 2026, 10:17

Type Values Removed Values Added
Summary
  • (es) Gitea no valida correctamente la titularidad de los proyectos en las operaciones de proyectos de la organización. Un usuario con permisos de escritura en proyectos de una organización podría modificar proyectos pertenecientes a una organización diferente.

29 Jan 2026, 21:48

Type Values Removed Values Added
References () https://blog.gitea.com/release-of-1.25.4/ - () https://blog.gitea.com/release-of-1.25.4/ - Release Notes
References () https://github.com/go-gitea/gitea/pull/36318 - () https://github.com/go-gitea/gitea/pull/36318 - Issue Tracking, Patch
References () https://github.com/go-gitea/gitea/pull/36373 - () https://github.com/go-gitea/gitea/pull/36373 - Issue Tracking, Patch
References () https://github.com/go-gitea/gitea/releases/tag/v1.25.4 - () https://github.com/go-gitea/gitea/releases/tag/v1.25.4 - Release Notes
References () https://github.com/go-gitea/gitea/security/advisories/GHSA-h4fh-pc4w-8w27 - () https://github.com/go-gitea/gitea/security/advisories/GHSA-h4fh-pc4w-8w27 - Broken Link
First Time Gitea
Gitea gitea
CPE cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*

23 Jan 2026, 22:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

22 Jan 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-22 22:16

Updated : 2026-07-15 02:18


NVD link : CVE-2026-20750

Mitre link : CVE-2026-20750

CVE.ORG link : CVE-2026-20750


JSON object : View

Products Affected

gitea

  • gitea
CWE
CWE-284

Improper Access Control