Hackers exploit critical auth bypass in Gitea Docker image
Reported exploitedGitea Docker imageOur summary
Attackers are actively exploiting a critical authentication bypass flaw in the official Docker image for Gitea, a self-hosted Git service. The vulnerability, tracked as CVE-2026-20896, allows unauthenticated users to impersonate any account—including admin—by manipulating the X-WEBAUTH-USER header. This affects deployments using the default configuration that trusts this header from any IP address. Security researchers confirmed real-world exploitation began just days after the advisory was issued. Gitea has released patched versions 1.26.3 and 1.26.4, urging all users to update immediately.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.