Gitea Improper Authorization Vulnerability in OAuth Sign-In Callback Re-Enables Disabled Accounts

Vulnerability

A vulnerability in Gitea's OAuth2 sign-in callback can improperly reactivate accounts that administrators have disabled. This issue is present in Gitea versions through 1.26.1. When a user authenticates via a linked external identity provider, the callback automatically restores their access, disregarding the administrator's disablement. As a result, the user regains full access to their repositories, organizations, and tokens, undermining administrative controls.

Impact

This vulnerability allows users to bypass account disablement, restoring their access and privileges, which could be problematic in cases of compromised accounts or employees who have left the organization.

Reproduction

To reproduce this vulnerability, first disable a user's account through the admin interface. Then, have the user sign in using an OAuth2 provider. The callback will reactivate the account, ignoring the previous disablement.

Remediation

Users can upgrade to Gitea version 1.26.4, which addresses this vulnerability.

Added: Jul 3, 2026, 10:23 PM
Updated: Jul 3, 2026, 10:23 PM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
1.3
exploitability
6.4
remediation
7.7
relevance
8.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.