{"id":"CVE-2026-73278","summary":"Gitea WebAuthn bypass during OAuth and OIDC sign-in","details":"Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.","aliases":["GHSA-92j2-6qcg-c28c"],"modified":"2026-10-08T02:51:50.598004700Z","published":"2026-10-06T19:33:54.375Z","database_specific":{"cna_assigner":"Gitea","cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73278.json"},"references":[{"type":"ADVISORY","url":"https://blog.gitea.com/release-of-1.27.2/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73278.json"},{"type":"ADVISORY","url":"https://github.com/go-gitea/gitea/releases/tag/v1.27.2"},{"type":"ADVISORY","url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-92j2-6qcg-c28c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73278"},{"type":"FIX","url":"https://github.com/go-gitea/gitea/pull/38805"},{"type":"FIX","url":"https://github.com/go-gitea/gitea/pull/38810"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/go-gitea/gitea","events":[{"introduced":"8df3d6575a3e07d38b264e5c1581e48aa4a02c88"},{"fixed":"1dac1bb2f8593d4319125fa6bca9283000a2ddc2"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"1.16.0"},{"last_affected":"1.27.1"}]}}],"versions":["v1.27.1","v1.27.0","v1.27.0-rc0","v1.28.0-dev","v1.27.0-dev","v1.26.0-dev","v1.25.0-dev","v1.24.0-dev","v1.22.0-rc1","v1.23.0-dev","v1.22.0-rc0","v1.21.0-rc0","v1.22.0-dev","v1.20.0-rc0","v1.21.0-dev","v1.20.0-dev","v1.19.0-rc0","v1.18.0-rc0","v1.19.0-dev","v1.18.0-dev","v1.17.0-dev","v1.16.0-rc1","v1.16.0-dev"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73278.json"}}],"schema_version":"1.9.0"}