PT-2026-107225 · Gitea · Gitea
CVE-2026-96404
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gitea (affected versions not specified)
Description
When the web installer is accessible and connected to a database that already contains users, such as when the
INSTALL LOCK variable is set to false, the system may issue an authenticated session without password verification. This occurs if the install form is submitted with an administrator username that matches an existing account. If the targeted account has administrator privileges, the attacker gains full administrative access, allowing them to perform actions such as changing the account password. Additionally, the reinstall confirmation is not required for databases containing only a single user.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitea