Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-73278: Gitea lets users log in without passkey via OAuth
CVE-2026-73278 · published 3 days ago
Summary
When people sign in to Gitea using an external service like OAuth or OpenID Connect, the system can skip the required security key check if that is the only two‑factor method set up. An attacker who can get past the external service could then access the account without the extra protection and could keep the link for future logins. Update Gitea to the newest version that corrects this behavior and consider adding another form of two‑factor authentication.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gitea | gitea | <= 1.27.1 |
Original advisory text
Gitea WebAuthn bypass during OAuth and OIDC sign-in
Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73278... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73278 Vendor Advisory
- https://github.com/go-gitea/gitea/security/advisories/GHSA-92j2-6qcg-c28c
- https://blog.gitea.com/release-of-1.27.2/
- https://github.com/go-gitea/gitea/pull/38805
- https://github.com/go-gitea/gitea/pull/38810
- https://github.com/go-gitea/gitea/releases/tag/v1.27.2
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-287Improper Authentication
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta