CVE-2026-24690: Gitea pull-request branch updates use insufficient permission checks
Published Jul 3, 2026
·Updated
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
Affected Software
1 affected component
Gitea Gitea<1.25.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Giteato a version that resolves this vulnerability.Fixed in 1.25.5
Event History
Jul 3, 2026
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-24690?
CVE-2026-24690 has a risk rating of 52, indicating a moderate level of severity.
2
How do I fix CVE-2026-24690?
To resolve CVE-2026-24690, upgrade Gitea to version 1.25.5 or later.
3
What versions are affected by CVE-2026-24690?
Gitea versions prior to 1.25.5 are affected by CVE-2026-24690.
4
What type of vulnerability is CVE-2026-24690?
CVE-2026-24690 involves insufficient permission checks for updating or rebasing pull request branches in Gitea.
5
Can CVE-2026-24690 lead to unauthorized access?
Yes, if exploited, CVE-2026-24690 can potentially allow unauthorized users to update or rebase pull request branches.