Authorization bypass through user-controlled key in Gitea - CVE-2026-57886
Published: July 14, 2026
Vulnerability details
The vulnerability allows a remote user to disclose private attachment content.
The vulnerability exists due to authorization bypass through user-controlled key in web issue/comment attachment handling when updating issue or comment attachments with attachment UUIDs. A remote user can submit a known attachment UUID through issue or comment edit flows to disclose private attachment content.
The issue can also alter the attachment's logical issue or comment association, and exploitation requires knowledge of a high-entropy attachment UUID.