---
id: CVE-2026-96404
title: >-
  When Gitea's web installer is reachable against a database that already
  contains users, such as after `INSTALL_LOCK` has been reset to `false`,
  submitting the install form with an administrator username matching an
  existing account issue…
summary: >-
  When Gitea's web installer is reachable against a database that already
  contains users, such as after `INSTALL_LOCK` has been reset to `false`,
  submitting the install form with an administrator username matching an
  existing account issue…
severity: none
vendor: Gitea
product: gitea.dev
affected:
  - gitea.dev <= 1.27.3
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:17:35.500'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96404'
references:
  - url: 'https://blog.gitea.com/release-of-28.0.0/'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/pull/39400'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/releases/tag/v28.0.0'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
  - url: 'https://github.com/go-gitea/gitea/security/advisories/GHSA-9h7g-h754-c8x2'
    label: 88ee5874-cf24-4952-aea0-31affedb7ff2
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T20:16:42.494Z'
---

## Overview

When Gitea's web installer is reachable against a database that already contains users, such as after `INSTALL_LOCK` has been reset to `false`, submitting the install form with an administrator username matching an existing account issued an authenticated session for that account without verifying its password. If the account is an administrator, the session grants full administrative access, including changing the account's password. Databases with a single user also did not require the reinstall confirmation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
