CVE-2026-20904
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
Affected (1)
Related CWEs
CWE-284
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-639
Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
References (5)
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Issue TrackingPatch
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Issue TrackingPatch
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Release Notes
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Broken Link
Timeline
No history available yet.