Gitea installer authentication bypass for existing accounts
Summary
| CVE | CVE-2026-96404 |
|---|---|
| State | PUBLISHED |
| Assigner | Gitea |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-06 20:17:35 UTC |
| Updated | 2026-10-06 20:17:35 UTC |
| Description | When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation. |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/go-gitea/gitea/releases/tag/v28.0.0 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | github.com | |
| github.com/go-gitea/gitea/pull/39400 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | github.com | |
| blog.gitea.com/release-of-28.0.0 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | blog.gitea.com | |
| github.com/go-gitea/gitea/security/advisories/GHSA-9h7g-h754-c8x2 | 88ee5874-cf24-4952-aea0-31affedb7ff2 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: https://github.com/vuductruong12 (en)
CNA: https://github.com/lilmingwa13 (en)
CNA: https://github.com/wxiaoguang (en)
There are currently no legacy QID mappings associated with this CVE.