CVE-2026-73278
Description
AI Translation Available
Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.
287
Improper Authentication
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Access Control
Potential Impacts:
Read Application Data
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based, ICS/OT
https://blog.gitea.com/release-of-1.27.2/
https://github.com/go-gitea/gitea/pull/38805
https://github.com/go-gitea/gitea/pull/38810
https://github.com/go-gitea/gitea/releases/tag/v1.27.2
https://github.com/go-gitea/gitea/security/advisories/GHSA-92j2-6qcg-c28c