PT-2026-107225 · Gitea · Gitea

CVE-2026-96404

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gitea (affected versions not specified)
Description When the web installer is accessible and connected to a database that already contains users, such as when the INSTALL LOCK variable is set to false, the system may issue an authenticated session without password verification. This occurs if the install form is submitted with an administrator username that matches an existing account. If the targeted account has administrator privileges, the attacker gains full administrative access, allowing them to perform actions such as changing the account password. Additionally, the reinstall confirmation is not required for databases containing only a single user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96404
GHSA-9H7G-H754-C8X2

Affected Products

Gitea