Improper access control in Gitea - CVE-2026-68957
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the issue-search API and web issue-search route when handling issue search requests for Limited-visibility users. A remote user can search for issues and read returned titles and bodies to disclose sensitive information.
Anonymous issue search does not return the same content.