Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-73278: Gitea lets users log in without passkey via OAuth

CVE-2026-73278 · published 3 days ago
Summary

When people sign in to Gitea using an external service like OAuth or OpenID Connect, the system can skip the required security key check if that is the only two‑factor method set up. An attacker who can get past the external service could then access the account without the extra protection and could keep the link for future logins. Update Gitea to the newest version that corrects this behavior and consider adding another form of two‑factor authentication.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
gitea gitea <= 1.27.1
Original advisory text
Gitea WebAuthn bypass during OAuth and OIDC sign-in
Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-287Improper Authentication
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-73278 · MITRE
Track software like this
Free during beta