What is CVE-2026-24059?
CVE-2026-24059 is a critical vulnerability in Gitea where the GET /api/v1/user/actions/runners/registration-token endpoint incorrectly creates a new runner registration token if none exists, despite being classified as read-only by API scope middleware. An attacker with a leaked `read:user` scoped token can exploit this to generate tokens, users should upgrade Gitea to the latest patched version and review token management policies.
Azərbaycanca: CVE-2026-24059 Gitea-da aşkar edilmiş kritik zəiflikdir. `/api/v1/user/actions/runners/registration-token` GET sorğusu API əhatə dairəsi middleware tərəfindən səhvən yalnız oxuna bilən kimi təsnif edilir, lakin əslində yeni runner qeydiyyat tokeni yaradır. Bu səbəbdən, `read:user` kimi məhdud icazələrə malik sızdırılmış tokeni ələ keçirən şəxs token yarada bilər, istifadəçilər Gitea-nı ən son versiyaya yeniləməli və token idarəetmə siyasətlərini nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What level of access permission does an attacker need to exploit CVE-2026-24059?
An attacker needs to obtain a leaked token with limited permissions such as `read:user`.
What security measures are recommended for users regarding CVE-2026-24059?
Users should upgrade Gitea to the latest patched version and review token management policies.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.