Email Management API Vulnerability in Gitea
CVE-2026-55986

Currently unrated

Key Information:

Vendor

Gitea

Vendor
CVE Published:
13 August 2026

What is CVE-2026-55986?

This vulnerability in Gitea's email management API allows unauthorized access by bypassing feature restrictions intended to manage credentials securely. This flaw can enable malicious actors to exploit the API, potentially leading to sensitive information exposure or unauthorized operations. Users are advised to update to the latest versions to mitigate this risk, as detailed in the Gitea release notes and security advisories.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

martijnperdaan52
.