Improper access control in Gitea - CVE-2026-68957

 

Improper access control in Gitea - CVE-2026-68957

Published: August 31, 2026


Vulnerability identifier: #VU146348
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68957
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the issue-search API and web issue-search route when handling issue search requests for Limited-visibility users. A remote user can search for issues and read returned titles and bodies to disclose sensitive information.

Anonymous issue search does not return the same content.


Affected software

Gitea

How to mitigate CVE-2026-68957

Install security update from vendor's website.

Gitea - update to 1.27.3

External References

Related Security Bulletins