daily cyber × ai intelligence

index

tagged

[CVE-2026-20896]

3 editions · 3 items

July 8, 2026

  • A critical Gitea authentication bypass, CVE-2026-20896, is being probed in the wild. Official Gitea Docker images up to 1.26.2 with reverse-proxy auth enabled trusted any source IP as a proxy, letting an attacker who reaches the container's HTTP port spoof X-WEBAUTH-USER and impersonate a known/guessable user — accessing repos and secrets. Fixed in 1.26.3/1.26.4; a public PoC/checker exists, and Sysdig observed first in-the-wild probing 13 days post-disclosure. SecurityWeek · Vulnerabilities & Exploits

in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM