CVE-2026-73278: fallo crítico en Gitea
Gitea WebAuthn bypass during OAuth and OIDC sign-in
Publicada el · Actualizada el
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.8epss 0.2%
probabilidad de explotación
0.2%top 94% de las CVE
explotación observada
noninguna fuente lo reporta
Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Gitea · GiteaCVEs relacionadas — Gitea
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-60004CRITICALCVE-2026-60004EPSS 24.0%KEVCVE-2019-1010314—CVE-2019-1010314EPSS 0.8%CVE-2019-1010261—CVE-2019-1010261EPSS 0.8%CVE-2026-34966HIGHGitea prior to 1.27.0 SSRF via Migration URI Fetch BypassEPSS 0.4%CVE-2025-69413MEDIUMCVE-2025-69413EPSS 0.4%CVE-2025-68938MEDIUMCVE-2025-68938EPSS 0.4%