CVE-2026-20750: Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/go-gitea/giteato a version that resolves this vulnerability.Fixed in 1.25.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20750?
CVE-2026-20750 is considered a high-severity vulnerability due to its potential for unauthorized project modifications across different organizations.
How do I fix CVE-2026-20750?
To fix CVE-2026-20750, upgrade Gitea to version 1.25.4 or later, which addresses the authorization bypass issue.
What type of vulnerability is CVE-2026-20750?
CVE-2026-20750 is categorized as an Insecure Direct Object Reference (IDOR) vulnerability affecting project ownership validation.
Who is affected by CVE-2026-20750?
Users with project write access in one organization on Gitea can be affected if they can modify projects belonging to other organizations.
What actions should be taken regarding CVE-2026-20750?
Organizations using affected versions of Gitea should prioritize updating their installations to secure against CVE-2026-20750.