CVE-2026-20750
Gitea does not properly validate project ownership in organization project operations. A user with project write access
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.
CRITICAL · CVSS 9.1
EPSS 0.00021
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0