CVE-2026-20888 | Gitea up to 1.25.3 Web Interface access control (GHSA-ccq9-c5hv-cf64 / EUVD-2026-4265)
A vulnerability identified as critical has been detected in Gitea up to 1.25.3. This impacts an unknown function of the component Web Interface. This manipulation causes improper access controls.
This vulnerability is registered as CVE-2026-20888. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.