PT-2026-50135 · Gitea+1 · Gitea+1

·

CVE-2026-25714

·

Published

2026-06-16

·

Updated

2026-07-30

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gitea (affected versions not specified)
Description An issue exists in the token public-only scope enforcement where a public-only scoped API token can access private organization data. This occurs due to two flaws: the endpoint '/user/orgs' is missing the checkTokenPublicOnly() validation, and the checkTokenPublicOnly() function uses a switch-case logic that only evaluates the first matching category, causing the user visibility check to be skipped for routes involving both user and organization categories.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10566
CVE-2026-25714
GHSA-8629-VC8R-5P58
GO-2026-5243
OPENSUSE-SU-2026:21483-1

Affected Products

Gitea
Red Os