CVE-2026-96404: Gitea installer authentication bypass for existing accounts

Published Oct 6, 2026
·
Updated

When Gitea's web installer is reachable against a database that already contains users, such as after INSTALLLOCK has been reset to false, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.

Affected Software

1 affected component
Gitea Gitea

Event History

Oct 6, 2026
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Instances where the web installer is reachable while the connected database already contains user accounts are exposed. This can occur after INSTALL_LOCK has been reset to false.

2

What does an attacker need to exploit it?

An attacker needs access to the reachable web installer and must submit the installation form using the username of an existing account. No password verification occurs for the matching account.

3

What is the impact if the targeted account is an administrator?

The attacker receives an authenticated session as that administrator, with full administrative access. This includes the ability to change the administrator account's password.

4

Does reinstall confirmation always protect against this behavior?

No. A database containing only one user did not require reinstall confirmation.

5

What should be checked when assessing exposure?

Check whether the web installer is reachable, whether INSTALL_LOCK is false, and whether the connected database contains existing users. Also determine whether any existing account, especially an administrator account, could have been targeted through the installer.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203