CVE-2026-96404

Summary

When Gitea's web installer is reachable against a database that already contains users, such as after INSTALL_LOCK has been reset to false, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.

Affected Software

VendorProductVersion RangeStatus
GiteaGitea0 <= 1.27.3affected

Weaknesses

References