UNKNOWN NVD
CVE-2026-96404
When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the i
When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.
References
- https://blog.gitea.com/release-of-28.0.0/
- https://github.com/go-gitea/gitea/pull/39400
- https://github.com/go-gitea/gitea/releases/tag/v28.0.0
- https://github.com/go-gitea/gitea/security/advisories/GHSA-9h7g-h754-c8x2
This unknown severity vulnerability was published on 2026-10-06 via NVD.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.