CVE 6.5 MEDIUM

Gitea: Broken access control in OpenID visibility toggle enables cross-user visibility changes_CVE-2026-20904

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Description

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.

Basic Information

ID CVE-2026-20904
Source Gitea
Published Jan 22, 2026 at 22:01
Modified Jan 23, 2026 at 21:53

Affected Product

Vendor Gitea
Product Gitea Open Source Git Server
Affected Versions Gitea Gitea Open Source Git Server 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.