CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-20750

Critical · CVSS 9.1

Gitea — Improper Access Control - Organization Project Ownership Validation Bypass

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-284, CWE-284

Description

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.

Search profile — drives PoC discovery

Symbols org projectproject write accessorganization project operationsproject ownership validationGHSA-h4fh-pc4w-8w27pull/36318pull/36373v1.25.4
Keywords CVE-2026-20750Gitea organization project ownership bypassGitea project write access cross-orgGHSA-h4fh-pc4w-8w27Gitea CWE-284 projectGitea improper access control projectgo-gitea organization project validationGitea v1.25.4 security fixGitea cross-organization project modification
Versions: < 1.25.4

Affected packages

Bitnami gitea 0 → 1.25.4
Go code.gitea.io/gitea 0 → 1.25.4
Go github.com/go-gitea/gitea 0 → 1.25.4

References

Status: enriched · ingested 2026-06-27T06:00:38.000Z · profiled 2026-06-30T18:30:14.000Z