CVE-2026-73278

Published: Ott 06, 2026 Last Modified: Ott 06, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.

287

Improper Authentication

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability Access Control
Potential Impacts:
Read Application Data Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies: Not Technology-Specific, Web Based, ICS/OT
View CWE Details
https://blog.gitea.com/release-of-1.27.2/
https://github.com/go-gitea/gitea/pull/38805
https://github.com/go-gitea/gitea/pull/38810
https://github.com/go-gitea/gitea/releases/tag/v1.27.2
https://github.com/go-gitea/gitea/security/advisories/GHSA-92j2-6qcg-c28c