CVE-2026-24059 | Gitea up to 1.25.4 API Scope Middleware registration-token privileges management
A vulnerability was found in Gitea up to 1.25.4. It has been rated as critical. Impacted is an unknown function of the file /api/v1/user/actions/runners/registration-token of the component API Scope Middleware. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2026-24059. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More