Improper access control in Gitea - CVE-2026-20800

 

Improper access control in Gitea - CVE-2026-20800

Published: July 14, 2026


Vulnerability identifier: #VU137413
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20800
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in /api/v1/user/starred and /api/v1/user/times when handling requests for user-starred repositories and tracked time entries. A remote user can query these endpoints after access revocation to disclose sensitive information.

The issue leaks metadata from private repositories, including repository objects and private issue titles, after the user's access has been revoked.


Affected software

Gitea

How to mitigate CVE-2026-20800

Install security update from vendor's website.

Gitea - update to 1.27.0

External References

Related Security Bulletins