Unrated severityNVD Advisory· Published Oct 6, 2026
CVE-2026-96404
CVE-2026-96404
Description
When Gitea's web installer is reachable against a database that already contains users, such as after INSTALL_LOCK has been reset to false, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.
Affected products
2Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.