CVE-2026-20888

CVE-2026-20888: Gitea Pull Requests Auto-Merge: Read-Only Users Can Cancel Scheduled Auto-Merge via Web Endpoint (Authorization Bypass)

Vendor Gitea
Product Gitea Open Source Git Server
Weakness CWE-284
Published January 22, 2026
Last update January 23, 2026

CVSS base score

What the vulnerability does

01Description

Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface. A user with read access to pull requests may be able to cancel auto-merges scheduled by other users.

Key dates

02Disclosure timeline

January 22, 2026 CVE published
January 23, 2026 Record updated