CVE-2026-73278

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-07); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-07: 1Mentions · 2026-10-08: 110-0710-08
Referenced assets1 URL
By indicator
Full discourse2 posts
  • The Hacker Wire@TheHackerWire

    🚨 CVE-2026-73278 (CVSS 9.8 Critical)OAuth2 and OIDC sign-in paths in Gitea fail to enforce WebAuthn challenges, allowing attackers authenticating via external IdP to bypass 2FA and hijack victim accounts.https://www.thehackerwire.com/vulnerability/CVE-2026-73278/ https://t.co/GkhC7xOyR0

    00010104
    176 followersView on X
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-73278 Vendor → Unknown Severity → Critical — CVSS 9.8 Product → Unknown Date → 2026-10-06 A critical vulnerability (Improper Authentication) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000056
    451 followersView on X

Explore more