Over 8,300 Gitea Servers Vulnerable to Code Execution Flaw

www.news4hackers.com-over-8-300-gitea-servers-vulnerable-to-code-execution-flaw-over-8-300-gitea-servers-vulnerable-to-code-execution-flaw

More than 8,300 Gitea servers remain exposed to remote code execution threats due to an unpatched critical vulnerability actively exploited in ongoing attacks, according to cybersecurity monitoring group Shadowserver.

Critical Vulnerability in Gitea

The flaw, designated CVE-2026-60004, enables authenticated adversaries to execute arbitrary system commands with elevated privileges by leveraging the diffpatch API endpoint to inject malicious code. Exploitation requires write access to a repository hosted on affected instances, but default self-registration settings allow unauthenticated users to create accounts and gain necessary permissions.

Exploitation Mechanism

Security researchers at Gitea confirmed that the diffpatch endpoint can be manipulated to deploy malicious Git hooks, granting attackers the ability to run shell commands under the Gitea service account.

Patch and Recommendations

A patch for the vulnerability was released on July 27 via version 1.27.1, with immediate upgrades recommended for all deployments. Shadowserver’s latest scan identified 8,393 internet-facing Gitea servers still vulnerable as of August 27, 2026.

Patch Release and Upgrade Recommendations

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified the flaw as actively exploited and mandated federal agencies to implement fixes by August 28 under Binding Operational Directive 26-04.

CISA’s Response

While specific attack details remain undisclosed, evidence suggests threat actors are deploying cryptocurrency mining malware on unpatched systems. CISA emphasized the severity of such vulnerabilities, noting their frequent use as entry points for malicious actors targeting enterprise infrastructure.

Active Exploitation and Threats

CISA highlighted the urgency of addressing these security gaps, as compromised servers could lead to data breaches, service disruptions, or unauthorized resource exploitation.

Additional Vulnerabilities

In addition to CVE-2026-60004, attackers have previously leveraged another critical flaw (CVE-2026-20896) in the official Gitea Docker image. This authentication bypass vulnerability affected instances using reverse proxy authentication headers, highlighting ongoing risks associated with misconfigured deployment practices.

Historical Context and Risks

Gitea, a self-hosted platform for code management and DevOps workflows, has over 400,000 installations globally and supports collaborative development through its open-source framework.

Impact and Urgency

Security teams are advised to prioritize patching efforts, review authentication configurations, and monitor for signs of malicious activity such as unexpected process executions or network traffic anomalies. Organizations relying on Gitea should also conduct regular security audits to identify and mitigate potential exposure vectors.

“Security researchers at Gitea confirmed that the diffpatch endpoint can be manipulated to deploy malicious Git hooks, granting attackers the ability to run shell commands under the Gitea service account.”



About Author

en_USEnglish