Incorrect authorization in Gitea - CVE-2026-55987
Published: July 14, 2026
Vulnerability details
The vulnerability allows a remote user to regain access to a deactivated account and obtain administrative access.
The vulnerability exists due to incorrect authorization in the OAuth2 sign-in callback when handling sign-in through an authentication source that does not issue refresh tokens. A remote user can sign in through the configured OAuth2 or OIDC provider to regain access to a deactivated account and obtain administrative access.
Only the "Activated" deactivation state is affected; accounts blocked with "Prohibit Login" remain unable to sign in.