Impact
Gitea’s OAuth2 and OpenID Connect sign‑in paths do not present a WebAuthn challenge when WebAuthn is the only second factor configured for an account. This flaw allows an attacker who can authenticate through the external identity provider to obtain a valid Gitea session without presenting the required passkey. The effect is that the attacker can impersonate the user for the duration of the session and potentially access all data and actions the user can perform.
Affected Systems
The vulnerability affects installations of Gitea that use OAuth2 or OIDC as an authentication method and have WebAuthn set as the sole second factor. Versions prior to the release that includes the fix – notably Gitea 1.27.2 and earlier – are impacted. Users with total TOTP as a second factor are not included in the reported scenario.
Risk and Exploitability
Because the flaw can be exploited entirely over the external identity flow, the attack vector is remote and requires only ability to authenticate to the configured identity provider. No local privileges are needed. The absence of an EPSS score and the fact that the vulnerability is not listed in CISA KEV suggest that public exploitation is not confirmed yet, but the potential for credential‑spoofing is high for any Gitea site using WebAuthn‑only second factors. The CVE’s impact is a complete bypass of the second‑factor authentication step.
OpenCVE Enrichment