CVE-2026-20897 | Gitea up to 1.25.3 access control (GHSA-rrq5-r9h5-pc7c / EUVD-2026-4264)
A vulnerability marked as critical has been reported in Gitea up to 1.25.3. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper access controls.
This vulnerability is reported as CVE-2026-20897. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.