Skip to main content
HIGH

CVE-2026-96404

Gitea installer authentication bypass for existing accounts

CVSS v3

8.1

HIGH

EPSS Score

—

exploit probability

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinsta

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Published
2026-10-06
Last Modified
2026-10-07

Frequently asked questions

What is CVE-2026-96404?

When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinsta

Is CVE-2026-96404 actively exploited?

Active exploitation of CVE-2026-96404 has not been confirmed.

What is the CVSS score for CVE-2026-96404?

CVE-2026-96404 has a CVSS v3 base score of 8.1 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.

Is CVE-2026-96404 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key