Improper access control in Gitea - CVE-2026-66849
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the package registry access check in determineAccessMode when handling requests for packages owned by Limited-visibility users. A remote user can enumerate and download package content to disclose sensitive information.
The issue affects restricted accounts that are logged in and applies to packages owned by Limited-visibility users.