CVE-2026-96404
N/A
N/A
Summary
When Gitea's web installer is reachable against a database that already contains users, such as after INSTALL_LOCK has been reset to false, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Gitea | Gitea | 0 <= 1.27.3 | affected |
Weaknesses
References
- https://github.com/go-gitea/gitea/security/advisories/GHSA-9h7g-h754-c8x2
- https://github.com/go-gitea/gitea/pull/39400
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.