CVE-2026-96404: Gitea installer authentication bypass for existing accounts
When Gitea's web installer is reachable against a database that already contains users, such as after INSTALLLOCK has been reset to false, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Instances where the web installer is reachable while the connected database already contains user accounts are exposed. This can occur after INSTALL_LOCK has been reset to false.
What does an attacker need to exploit it?
An attacker needs access to the reachable web installer and must submit the installation form using the username of an existing account. No password verification occurs for the matching account.
What is the impact if the targeted account is an administrator?
The attacker receives an authenticated session as that administrator, with full administrative access. This includes the ability to change the administrator account's password.
Does reinstall confirmation always protect against this behavior?
No. A database containing only one user did not require reinstall confirmation.
What should be checked when assessing exposure?
Check whether the web installer is reachable, whether INSTALL_LOCK is false, and whether the connected database contains existing users. Also determine whether any existing account, especially an administrator account, could have been targeted through the installer.