CVE-2026-20904 - Gitea: Broken access control in OpenID visibility toggle enables cross-user visibility changes
CVE ID : CVE-2026-20904
Published : Jan. 22, 2026, 10:16 p.m. | 1 hour, 28 minutes ago
Description : Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Jan. 22, 2026, 10:16 p.m. | 1 hour, 28 minutes ago
Description : Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...