Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rw22-5hhq-pfpf | Gitea does not properly validate project ownership in organization project operations |
Thu, 29 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitea:gitea:*:*:*:*:*:-:*:* |
Tue, 27 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 23 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitea
Gitea gitea |
|
| Vendors & Products |
Gitea
Gitea gitea |
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization. | |
| Title | Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR) | |
| Weaknesses | CWE-284 | |
| References |
|
Status: PUBLISHED
Assigner: Gitea
Published:
Updated: 2026-01-23T21:54:39.525Z
Reserved: 2026-01-08T23:02:37.565Z
Link: CVE-2026-20750
Updated: 2026-01-23T21:12:23.797Z
Status : Analyzed
Published: 2026-01-22T22:16:17.370
Modified: 2026-01-29T21:48:07.563
Link: CVE-2026-20750
OpenCVE Enrichment
Updated: 2026-04-18T19:00:08Z
Github GHSA