A vulnerability classified as problematic was found in Gitea up to 1.26.4. This issue affects some unknown processing of the component Fork-PR Actions. Such manipulation leads to improper privilege management.

This vulnerability is referenced as CVE-2026-58416. It is possible to launch the attack remotely. No exploit is available.