Improper access control in Gitea - CVE-2026-68964
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the user SSH and GPG key API endpoints when handling requests for limited-visibility users. A remote user can send crafted API requests to disclose sensitive information.
The issue affects restricted accounts, which can access SSH public keys, GPG keys, fingerprints, and GPG-embedded email addresses of users whose profile visibility is set to Limited.