« Volver al listado

CVE-2026-96404

Estado: Pendiente de análisisAlta (8.1)—

When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-96404",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-96404",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-10-07T14:26:36.461394Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2",
      "affectedData": [
        {
          "vendor": "Gitea",
          "product": "Gitea",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "1.27.3"
            }
          ],
          "packageName": "gitea.dev",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-10-06T20:17:35.500",
  "references": [
    {
      "url": "https://blog.gitea.com/release-of-28.0.0/",
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    },
    {
      "url": "https://github.com/go-gitea/gitea/pull/39400",
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    },
    {
      "url": "https://github.com/go-gitea/gitea/releases/tag/v28.0.0",
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    },
    {
      "url": "https://github.com/go-gitea/gitea/security/advisories/GHSA-9h7g-h754-c8x2",
      "source": "88ee5874-cf24-4952-aea0-31affedb7ff2"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation."
    }
  ],
  "lastModified": "2026-10-07T15:17:58.800",
  "sourceIdentifier": "88ee5874-cf24-4952-aea0-31affedb7ff2"
}