CVE-2026-20909: Gitea tracked-time list endpoint has insufficient permission checks
Published Jul 3, 2026
·Updated
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
Affected Software
1 affected component
Gitea Gitea<1.25.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Giteato a version that resolves this vulnerability.Fixed in 1.25.5
Event History
Jul 3, 2026
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-20909?
The severity of CVE-2026-20909 is classified as medium with a score of 5.3.
2
What issues does CVE-2026-20909 present?
CVE-2026-20909 presents insufficient permission checks when listing tracked time entries in Gitea.
3
How do I fix CVE-2026-20909?
To fix CVE-2026-20909, upgrade to Gitea version 1.25.5 or later, which includes the necessary permission checks.
4
Which versions of Gitea are affected by CVE-2026-20909?
Gitea versions before 1.25.5 are affected by CVE-2026-20909.
5
When was CVE-2026-20909 published?
CVE-2026-20909 was published on July 3, 2026.