CVE Tools
Back to feed
Exploited in the wild Gitea Docker image web-app Gitea auth-bypass

Hackers exploit critical auth bypass in Gitea Docker image

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Attackers are actively exploiting a critical authentication bypass flaw in the official Docker image for Gitea, a self-hosted Git service. The vulnerability, tracked as CVE-2026-20896, allows unauthenticated users to impersonate any account—including admin—by manipulating the X-WEBAUTH-USER header. This affects deployments using the default configuration that trusts this header from any IP address. Security researchers confirmed real-world exploitation began just days after the advisory was issued. Gitea has released patched versions 1.26.3 and 1.26.4, urging all users to update immediately.