PT-2026-4287 · Gitea+1 · Gitea+1
Spingarbor
·
Published
2026-01-22
·
Updated
2026-02-24
·
CVE-2026-20736
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Gitea (affected versions not specified)
Description
Gitea does not correctly validate the repository context during attachment deletion. A user who uploaded an attachment to a repository might be able to delete it even after losing access to that repository by submitting the request through a different repository they are authorized to access. This occurs because the system fails to properly confirm the user's permission to delete the attachment within the original repository.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitea
Red Os