Description
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
Published: 2026-07-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Gitea Open Source Git Server versions before 1.25.5 have an insufficient permission check on the tracked‑time list API endpoint. The flaw is an improper access control vulnerability (CWE‑284) that allows any user who can reach the API to retrieve time‑tracking records without proper authorization. The attack does not modify data or affect service availability; it only exposes potentially sensitive development activity and workload information to unauthorized parties.

Affected Systems

All installations of Gitea Open Source Git Server running a version older than 1.25.5 are impacted. The vulnerability is independent of deployment context and can be triggered by any user with network access to the API endpoint.

Risk and Exploitability

The EPSS score of less than 1% indicates a very low probability of exploitation at the time of this analysis, while a CVSS score of 5.3 reflects moderate severity. The vulnerable endpoint is presumably reachable over any network path that can access the Gitea instance, which is inferred from the fact that the flaw involves an API. No elevated privileges or system compromise are required, and the vulnerability does not compromise availability or data integrity. The exposure of time‑tracking information represents a confidentiality breach that could assist in further malicious reconnaissance.

Generated by OpenCVE AI on July 23, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Gitea to version 1.25.5 or later.
  • Limit network exposure of the tracked‑time API, allowing access only from trusted hosts or internal networks.
  • Enforce role‑based permissions so that viewing of time‑tracking data is restricted to authorized user groups.

Generated by OpenCVE AI on July 23, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Gitea
Gitea gitea Open Source Git Server
Vendors & Products Gitea
Gitea gitea Open Source Git Server

Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
Title Gitea tracked-time list endpoint has insufficient permission checks
Weaknesses CWE-284
References

Subscriptions

Gitea Gitea Open Source Git Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-07-07T17:00:40.149Z

Reserved: 2026-02-22T15:13:33.704Z

Link: CVE-2026-20909

cve-icon Vulnrichment

Updated: 2026-07-07T15:35:19.539Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T16:30:09Z

Weaknesses