ID:12966 - Exploit for Improper access control in Gitea - CVE-2026-20896

 
Main Vulnerability Database Exploits ID:12966 - Exploit for Improper access control in Gitea - CVE-2026-20896

ID:12966 - Exploit for Improper access control in Gitea - CVE-2026-20896

Published: August 21, 2026


Vulnerability identifier: #VU135010
Vulnerability risk: High
CVE-ID: CVE-2026-20896
CWE-ID: CWE-284
Exploitation vector: Remote access
Vulnerable software:
Gitea

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to impersonate arbitrary users.

The vulnerability exists due to improper access control in reverse proxy authentication handling when processing the X-WEBAUTH-USER header from direct HTTP requests. A remote attacker can send a specially crafted request with an X-WEBAUTH-USER header to impersonate arbitrary users.

Only Docker image deployments are affected, and exploitation requires ENABLE_REVERSE_PROXY_AUTHENTICATION to be enabled.


Remediation

Install security update from vendor's website.