Impact
The vulnerability allows an attacker to bypass restrictions on the Email Management API, enabling unauthorized modification or retrieval of credential management data. This flaw falls under CWE‑284, indicating missing or improperly enforced authorization controls, and can undermine the confidentiality and integrity of authentication information.
Affected Systems
The only vendor listed is Gitea, an open‑source Git server. The CVE data does not specify exact version numbers that contain the flaw. The advisory references point to the 1.27.0 release, which presumably contains the fix, but administrators should verify the exact version that patches the issue.
Risk and Exploitability
The CVSS score of 5.4 classifies this as medium severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not included in the CISA KEV list. The description does not detail the specific attack vector; the most likely scenario inferred from the API context is that an authenticated API user could exploit the bypass. Environments where the Email Management API is exposed to untrusted networks or lacks strict access controls are at higher risk, though no public exploits have been reported.
OpenCVE Enrichment