CVE-2026-96404highCWE-287

CVE-2026-96404: high-severity vulnerability in Gitea

Gitea installer authentication bypass for existing accounts

Published · Updated

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 0.2%
exploitation probability
0.2%top 96% of all CVEs
observed exploitation
nono source reports it
When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Gitea · Gitea