8.1
CVE-2026-96404
- EPSS 0.41%
- Veröffentlicht 06.10.2026 19:25:28
- Zuletzt bearbeitet 07.10.2026 15:17:58
- Erkennungen
Gitea installer authentication bypass for existing accounts
When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGitea
≫
Produkt
Gitea
Default Statusunaffected
Version <=
1.27.3
Version
0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.41% | 0.335 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://blog.gitea.com/release-of-28.0.0/
https://github.com/go-gitea/gitea/releases/tag/v28.0.0
https://github.com/go-gitea/gitea/security/advisories/GHSA-9h7g-h754-c8x2
https://github.com/go-gitea/gitea/pull/39400