
Gitea has an authorization bypass (CVE-2026-20750) allowing cross-organization project access. Update to 1.25.4. #Gitea #Infosec #AuthBypass https://www.pulsepatch.io/posts/cve-2026-20750-gitea-authorization-bypass-idor
Post summary
This post highlights CVE-2026-20750, an authorization bypass in Gitea that permits cross‑organization project access, and advises users to upgrade to version 1.25.4 to remediate the issue.
