Skip to main content
MEDIUM

CVE-2026-20904

CVSS v3

6.5

MEDIUM

EPSS Score

0.0 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.

Technical details

CVSS v3 Vector
3.1
Published
2026-01-22
Last Modified
2026-01-29

Frequently asked questions

What is CVE-2026-20904?

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.

Is CVE-2026-20904 actively exploited?

Active exploitation of CVE-2026-20904 has not been confirmed. The EPSS score is 0.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-20904?

CVE-2026-20904 has a CVSS v3 base score of 6.5 (MEDIUM severity), with vector string 3.1.

Is CVE-2026-20904 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key