Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-20896 — this is a modified POC of rz1027 for CVE-2026-20896 | Kitploit
Tools/GitHubGitHub/xaoczenon/cve-2026-20896
Vulnerability AnalysisExploitationWeb Application ExploitationAuthenticationLearning & EducationLabs & Practice
GitHubxaoczenon/cve-2026-20896

CVE-2026-20896

this is a modified POC of rz1027 for CVE-2026-20896

View Repository
6422 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-20896 Lab

This repository provides a small, self-contained lab for exploring the CVE-2026-20896 issue in a controlled and authorized environment.

Overview

The lab includes:

  • poc.py: my customized proof-of-concept script that demonstrates the issue and exports browser-ready cookie files
  • detect.py: a checker based on the original project at https://github.com/rz1027/CVE-2026-20896
  • docker-compose.yml: a local Gitea lab setup based on the same original reference

Purpose

This project is intended strictly for education, research, and authorized security testing. It should only be used against systems you own or are explicitly authorized to test.

Quick Start

  1. Start the lab environment:

    docker compose up -d
    
  2. Verify that the service is reachable:

    python3 detect.py http://localhost:3000
    
  3. Run the proof-of-concept:

    python3 poc.py http://localhost:3000 admin
    

How It Works

The vulnerability is related to reverse-proxy authentication handling in Gitea. When reverse-proxy authentication is enabled, Gitea can trust the X-WEBAUTH-USER header if the trusted proxy configuration is too permissive.

In a vulnerable setup, an attacker who can reach the service directly may be able to spoof this header and impersonate another user. The PoC demonstrates that behavior in a controlled environment and exports cookies that can be imported into a browser for testing purposes.

Disclaimer

This repository is provided for educational and authorized security testing only.

By using this project, you agree that:

  • you have explicit permission to test the target system,
  • you will not use it against any unauthorized service,
  • you are solely responsible for your actions and any consequences that result.

The authors and contributors assume no liability for misuse or damage.

Notes

  • The lab uses Gitea 1.26.2, which is the vulnerable version referenced in the related discussion.
  • The scripts are intended for local, safe, and authorized testing only.
  • If you are testing a real deployment, ensure you have written permission before proceeding.

Attribution

The original reference for the detection logic and lab setup is:

  • https://github.com/rz1027/CVE-2026-20896

This repository uses that work as a reference for the lab environment and detection approach. The PoC script in poc.py has been customized and is presented as my own implementation.

Please preserve attribution when reusing or adapting this work.

License

This project is licensed under the MIT License. See LICENSE for details.

Download Tool