CVE-2026-20888

Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:*

History

No history.

Information

Published : 2026-01-22 22:16

Updated : 2026-01-29 22:00


NVD link : CVE-2026-20888

Mitre link : CVE-2026-20888

CVE.ORG link : CVE-2026-20888


JSON object : View

Products Affected

gitea

  • gitea
CWE
CWE-284

Improper Access Control

CWE-862

Missing Authorization