Количество 5
Количество 5
CVE-2026-55987
A flaw was found in Gitea. An attacker can reactivate an administrator-deactivated account by signing in via OAuth2, specifically when using authentication sources that do not utilize refresh tokens. This bypasses intended security controls, allowing unauthorized access to previously deactivated accounts.
CVE-2026-55987
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
ROS-20260813-80-0030
Уязвимость gitea
ROS-20260813-73-0030
Уязвимость gitea
GHSA-vrhc-jjfc-m3m3
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55987 A flaw was found in Gitea. An attacker can reactivate an administrator-deactivated account by signing in via OAuth2, specifically when using authentication sources that do not utilize refresh tokens. This bypasses intended security controls, allowing unauthorized access to previously deactivated accounts. | CVSS3: 3.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-55987 OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
ROS-20260813-80-0030 Уязвимость gitea | CVSS2: 8.5 | 0% Низкий | около 1 месяца назад | |
ROS-20260813-73-0030 Уязвимость gitea | CVSS2: 8.5 | 0% Низкий | около 1 месяца назад | |
GHSA-vrhc-jjfc-m3m3 Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009) | CVSS3: 8.1 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу