Gitea CVE-2026-20896, Auth.js GHSA-7rqj-j65f-68wh and Anritsu CVE-2026-3356 show pre-operation authentication checks failing in 2026
Gitea, Auth.js and Anritsu show the same access-control design failure: trust is established before the operation, then later code consumes authority that was never proven at the point of use.























































