Skip to content

Critical Gitea Vulnerability Allows Unauthenticated Reading of Server Files via Org-Mode Markup

Bottom line: A critical Gitea vulnerability (CVE-2026-59774, CVSS 9.8) allows unauthenticated reading of server files via Org-Mode markup in versions 1.22.1 through 1.27.0 and has been fixed in version 1.27.1.

In the self-hosted Git platform Gitea, a critical vulnerability enables attackers without any login to read arbitrary files accessible to the service account. Affected are versions 1.22.1 through 1.27.0; a patch is available with version 1.27.1.

The flaw is tracked as CVE-2026-59774 and rated critical with a CVSS score of 9.8. Successful exploitation requires only a public repository and crafted Org-Mode markup. Neither a login to the system nor write access to a repository is required to read files accessible to the service account.

For operators of Gitea instances, this poses a direct risk to the confidentiality of configuration files, credentials, or other sensitive information stored on the server and readable by the service account. Since the vulnerability can be exploited without authentication and without special privileges, the barrier to attack drops significantly — publicly accessible Gitea instances with at least one public repository are fundamentally exposed.

CISOs with self-hosted Gitea environments should promptly check which version is in use and prioritize updating to 1.27.1 or later. It is also advisable to review the service account’s permissions to limit potential damage in the event of an instance that was not patched in time, as well as to examine access logs for indications of exploitation that may have already occurred during the vulnerability window.


Source: thehackernews.com · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: