Critical Gitea Vulnerability Exposes Server Files to Unauthenticated Attackers

Critical Gitea Vulnerability Exposes Server Files to Unauthenticated Attackers

First seen 5 Aug 2026, 14:08 UTC ThehackernewsFeeds.4Sysops 74% similarity 72.0

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Gitea, identified as CVE-2026-59774, allows unauthenticated attackers to read files accessible to the service account via crafted Org-mode markup. This flaw affects Gitea versions 1.22.1 through 1.27.0 and has been patched in version 1.27.1. The vulnerability poses a significant risk to organizations using affected versions, as it can lead to unauthorized access to sensitive server files. The issue was disclosed on August 5, 2026, and organizations are urged to update their Gitea installations immediately to mitigate risks. No evidence of active exploitation has been reported yet, but the potential for abuse remains high.

Key Points: • CVE-2026-59774 allows unauthenticated file access in Gitea versions 1.22.1 to 1.27.0. • The vulnerability is patched in Gitea version 1.27.1, released on August 5, 2026. • Organizations using affected versions are strongly advised to update immediately.

ThreatCluster AI How this analysis works

Timeline

2026-08-05
CVE-2026-59774 disclosed
A critical vulnerability in Gitea allows unauthenticated file access via Org-mode markup, affecting versions 1.22.1 to 1.27.0.
Feeds.4Sysops
2026-08-05
Patch released for Gitea
Gitea version 1.27.1 is released to address the critical vulnerability CVE-2026-59774.
Thehackernews

Community

Browse all →