CVE-2026-20912: CWE-284: Improper Access Control in Gitea Gitea Open Source Git Server
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.
AI Analysis
Technical Summary
Gitea's improper validation of repository ownership when associating attachments with releases can lead to unauthorized access. Specifically, an attachment from a private repository can be linked to a release in a separate public repository, bypassing intended access restrictions. This vulnerability is classified under CWE-284 (Improper Access Control) and related CWEs, indicating a failure to enforce proper authorization checks. The CVSS v3.1 base score is 9.1 (critical), reflecting the high impact on confidentiality and integrity without requiring privileges or user interaction.
Potential Impact
An attacker can gain unauthorized access to attachments originally uploaded to private repositories by linking them to releases in public repositories. This leads to a confidentiality breach, exposing potentially sensitive data to unauthorized users. The integrity of repository data can also be impacted due to improper access control. Availability is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Users should monitor the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-20912 for updates on patches or official mitigations. Until a fix is available, restrict repository release attachment operations to trusted users and review repository permissions carefully to minimize exposure risk.
CVE-2026-20912: CWE-284: Improper Access Control in Gitea Gitea Open Source Git Server
Description
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to unauthorized users.
CVSS v3.1
Score 9.1critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Gitea's improper validation of repository ownership when associating attachments with releases can lead to unauthorized access. Specifically, an attachment from a private repository can be linked to a release in a separate public repository, bypassing intended access restrictions. This vulnerability is classified under CWE-284 (Improper Access Control) and related CWEs, indicating a failure to enforce proper authorization checks. The CVSS v3.1 base score is 9.1 (critical), reflecting the high impact on confidentiality and integrity without requiring privileges or user interaction.
Potential Impact
An attacker can gain unauthorized access to attachments originally uploaded to private repositories by linking them to releases in public repositories. This leads to a confidentiality breach, exposing potentially sensitive data to unauthorized users. The integrity of repository data can also be impacted due to improper access control. Availability is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch links are provided in the available data. Users should monitor the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-20912 for updates on patches or official mitigations. Until a fix is available, restrict repository release attachment operations to trusted users and review repository permissions carefully to minimize exposure risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Gitea
- Date Reserved
- 2026-01-08T23:02:37.548Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-20912","vendor":"Red Hat"}]
Threat ID: 6972a2c84623b1157c932842
Added to database: 01/22/2026, 22:20:56 UTC
Last enriched: 07/15/2026, 08:32:16 UTC
Last updated: 09/10/2026, 19:36:52 UTC
Views: 289
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.