Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Gitea Vulnerability Allows File Access Without Authentication

Gitea Vulnerability Allows File Access Without Authentication

Posted on August 5, 2026 By CWS

Critical Vulnerability Discovered in Gitea

Versions 1.22.1 through 1.27.0 of Gitea, the self-hosted Git service, have been found vulnerable to a critical flaw that allows unauthenticated attackers to access files. This issue requires neither login credentials nor repository write access; a public repository and specially crafted Org-mode markup are sufficient for exploitation. The vulnerability has been addressed in version 1.27.1.

Details of the Vulnerability

Identified as CVE-2026-59774, this vulnerability received a CVSS score of 9.8, marking it as critical. The advisory, released on August 2, noted the flaw’s potential for severe exploitation. Alongside this, Gitea 1.27.1 also resolved CVE-2026-60004, a separate remote code execution vulnerability.

Cloud-based Gitea instances will undergo automatic updates during maintenance windows, while self-hosted versions require immediate manual updates. The vulnerability is not a direct path to remote code execution but could lead to it if specific conditions are met, as outlined in Gitea’s advisory.

How the Flaw Operates

The flaw involves Gitea’s markup rendering endpoint, particularly affecting Org-mode processing. The endpoint, accessed via POST requests, allows optional sign-in and verifies repository access. Public repositories with code units enabled are susceptible to this attack path.

The breach originates from Gitea’s Org-mode renderer, which improperly utilized the go-org library’s default ReadFile callback, allowing unauthorized file reads. Attackers can exploit this by submitting Org-mode markup with the Mode: file directive to access files the service account can read. The issue has been resolved in a recent patch that ensures Org-mode paths are rendered as plain text.

Security Measures and Recommendations

Administrators are advised to scrutinize anonymous POST requests to the markup endpoint, especially those related to Org-mode or absolute file paths. If there’s a suspicion of attempted exploitation, it’s crucial to review repository hook directories for any unexpected files.

While no public exploits have been reported, and the vulnerability has not been listed in CISA’s Known Exploited Vulnerabilities catalog, precautionary measures should be taken. The advisory suggests rotating sensitive credentials if the vulnerability is suspected to have been exploited.

Recent Security Work at Gitea

This vulnerability is part of a series of security issues Gitea has addressed recently. In June, a significant reverse-proxy authentication bypass was patched, which had been actively probed soon after its disclosure. In May, a container-registry access-control flaw impacted thousands of deployments worldwide.

In conclusion, while Gitea has moved swiftly to address these vulnerabilities, administrators should remain vigilant, ensure systems are updated, and review security protocols to mitigate potential risks.

The Hacker News Tags:CVE-2026-59774, Cybersecurity, DevOps, Git platform, Gitea, Org-mode, remote code execution, security patch, self-hosted, Vulnerability

Post navigation

Previous Post: EtherRAT Malware Propagation via Remote Tasks on Windows
Next Post: Data Breach Affects 311,000 at Brown Health Group

Related Posts

China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Southeast Asia China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Southeast Asia The Hacker News
Critical Flaw in Ruflo Allows Remote Code Execution Critical Flaw in Ruflo Allows Remote Code Execution The Hacker News
Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine The Hacker News
Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More Firewall Exploits, AI Data Theft, Android Hacks, APT Attacks, Insider Leaks & More The Hacker News
Urgent 12-Hour Patch Rule Set by CERT-In for AI Threats Urgent 12-Hour Patch Rule Set by CERT-In for AI Threats The Hacker News
Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Raises Alert on Apache Tomcat Encryption Flaw
  • Data Breach Affects 311,000 at Brown Health Group
  • Gitea Vulnerability Allows File Access Without Authentication
  • EtherRAT Malware Propagation via Remote Tasks on Windows
  • SAFE Guidelines Aim to Standardize AI Incident Reporting

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Raises Alert on Apache Tomcat Encryption Flaw
  • Data Breach Affects 311,000 at Brown Health Group
  • Gitea Vulnerability Allows File Access Without Authentication
  • EtherRAT Malware Propagation via Remote Tasks on Windows
  • SAFE Guidelines Aim to Standardize AI Incident Reporting

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark