
CVE-2026-20896
Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")
authenticationeducationexploitation+5
6

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")

Technical analysis and PoC of CVE-2026-52824: default APP_SECRET in the Kimai Docker image enabling unauthenticated login link forgery. Affects <=…