Description
Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Update
AI Analysis

Impact

Gitea’s OAuth2 and OpenID Connect sign‑in paths do not present a WebAuthn challenge when WebAuthn is the only second factor configured for an account. This flaw allows an attacker who can authenticate through the external identity provider to obtain a valid Gitea session without presenting the required passkey. The effect is that the attacker can impersonate the user for the duration of the session and potentially access all data and actions the user can perform.

Affected Systems

The vulnerability affects installations of Gitea that use OAuth2 or OIDC as an authentication method and have WebAuthn set as the sole second factor. Versions prior to the release that includes the fix – notably Gitea 1.27.2 and earlier – are impacted. Users with total TOTP as a second factor are not included in the reported scenario.

Risk and Exploitability

Because the flaw can be exploited entirely over the external identity flow, the attack vector is remote and requires only ability to authenticate to the configured identity provider. No local privileges are needed. The absence of an EPSS score and the fact that the vulnerability is not listed in CISA KEV suggest that public exploitation is not confirmed yet, but the potential for credential‑spoofing is high for any Gitea site using WebAuthn‑only second factors. The CVE’s impact is a complete bypass of the second‑factor authentication step.

Generated by OpenCVE AI on October 6, 2026 at 20:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch that is included in Gitea 1.27.2 or later by upgrading the Gitea instance to a version that contains the fix.
  • If an upgrade cannot be performed immediately, disable or restrict OAuth2 and OIDC sign‑in for accounts that rely solely on WebAuthn, or enforce WebAuthn challenge validation during the OAuth flow through configuration changes if available.
  • Monitor authentication logs for anomalous logins, especially those originating from unfamiliar IP addresses, and review the configuration of external identity providers to ensure they are not unintentionally exposing the WebAuthn bypass path.

Generated by OpenCVE AI on October 6, 2026 at 20:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.
Title Gitea WebAuthn bypass during OAuth and OIDC sign-in
Weaknesses CWE-287
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Gitea

Published:

Updated: 2026-10-06T19:33:54.375Z

Reserved: 2026-08-13T16:50:59.760Z

Link: CVE-2026-73278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:29.000

Modified: 2026-10-06T20:17:29.000

Link: CVE-2026-73278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:00:06Z

Weaknesses