CVE-2026-96404

high

Description

When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.

References

https://github.com/go-gitea/gitea/security/advisories/GHSA-9h7g-h754-c8x2

https://github.com/go-gitea/gitea/releases/tag/v28.0.0

https://github.com/go-gitea/gitea/pull/39400

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93923

https://blog.gitea.com/release-of-28.0.0/

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.1

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00413