PT-2026-4287 · Gitea+1 · Gitea+1

Spingarbor

·

Published

2026-01-22

·

Updated

2026-02-24

·

CVE-2026-20736

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Gitea (affected versions not specified)
Description Gitea does not correctly validate the repository context during attachment deletion. A user who uploaded an attachment to a repository might be able to delete it even after losing access to that repository by submitting the request through a different repository they are authorized to access. This occurs because the system fails to properly confirm the user's permission to delete the attachment within the original repository.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BIT-GITEA-2026-20736
CVE-2026-20736
GHSA-HGR3-X44X-33HX
GHSA-JR6H-PWWP-C8G6
GO-2026-4367
SUSE-SU-2026:0403-1

Affected Products

Gitea
Red Os