CVE-2026-24791

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes


We have discovered 391 live websites that are affected by CVE-2026-24791.

Run a Free Instant Scan




Affected Software

Product  Gitea
Category Dev Tools
Vulnerable Domains391 live websites (52% of Gitea install base)
Vulnerable Versions
  • from 1.22.3 through 1.26.1
Vulnerable Versions Count24 versions ( 36% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • kamil-sawicki (reporter)

Website Distribution by Country

Number of websites using CVE-2026-24791
United States85 websites



Germany105 websites
France50 websites
Singapore27 websites
Russia23 websites
China17 websites
GB11 websites
Czech Republic7 websites
Netherlands7 websites
Canada6 websites

Website Distribution by TLD

Number of websites using CVE-2026-24791
.com98 websites
.net37 websites
.org36 websites
.de34 websites
.ru21 websites
.fr13 websites
.eu9 websites
.nl7 websites
.info5 websites
.cz5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-24791

Top websites that are affected by CVE-2026-24791. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.********.com United States***,***
*****.**********.eu Germany***,***
******************.com United States*,***,***
***.*******.fi Finland*,***,***
***.*********.rip Germany*,***,***
*********.nl United States*,***,***
***.************.com Singapore*,***,***
****.as United States*,***,***
***.**********.org Germany*,***,***
***.************.org United States*,***,***
See full domain list

FAQ

CVE-2026-24791 is Incorrect Authorization in Gitea
A total of 391 websites have been identified as vulnerable to CVE-2026-24791, based on global website indexing conducted by WebTechSurvey.
The Gitea is affected by the CVE-2026-24791 vulnerability.
Gitea versions up to and including 1.26.1 are vulnerable to CVE-2026-24791.