CVE-2026-58424PoC

MEDIUMCVSS 8.9 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Permanent Fork PR Workflow Approval Gate Bypass

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-732CWE-863

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-08-03)
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-07-03: 2Mentions · 2026-07-04: 1Mentions · 2026-08-03: 3PoC Mentioned / Linked · 2026-08-03: 3Exploit Tool / Code · 2026-08-03: 2Patch / Workaround · 2026-07-04: 1Technical Details · 2026-07-03: 2Technical Details · 2026-07-04: 1Technical Details · 2026-08-03: 307-0307-0408-03
Signal classification3 categories
PoC
350.0%
Disclosure
233.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-07-032
Disclosure2
2026-07-041
Patch1
2026-08-033
PoC3
Full discourse6 posts
  • ThreatWire@ThreatWire_
    PoC

    🚨 A public PoC has been released for CVE-2026-58424 affecting Gitea The flaw allows repository writers to execute arbitrary shell commands via a malicious Git hook, potentially leading to RCE on default configurations 🔗 https://github.com/imbas007/CVE-2026-60004-POC #Gitea #RCE #CVE #CyberSecurity

    Post summary

    A public PoC for CVE-2026-58424 has been released; the flaw allows repository writers to execute arbitrary shell commands via malicious Git hooks, posing an RCE risk on default Gitea configurations.

    05026111.5K
    1.5K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-58424 PT ID: PT-2026-55657 Vendor: Gitea Product: Gitea Description: Repository writers can execute arbitrary shell commands as the Gitea service account by planting a malicious Git hook. On instances with default configurations, external users can register, create a repository, and obtain the necessary write access to perform this action. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-55657 • https://github.com/imbas007/CVE-2026-60004-POC #dbugs_vuln

    Post summary

    A PoC/exploit for CVE‑2026‑58424 has been disclosed, showing that Gitea repository writers can run arbitrary shell commands via malicious Git hooks. No evidence of active exploitation, patching, or false‑positive status is provided.

    0201631.8K
    3.5K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-58424 PT ID: PT-2026-55657 Vendor: Gitea Product: Gitea Open Source Git Server Description: Permanent Fork PR Workflow Approval Gate Bypass References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-55657 • https://github.com/bridgeralderson/cve-2026-58424 #dbugs_vuln

    Post summary

    A PoC for CVE-2026-58424, a Gitea approval‑gate bypass, has been published on GitHub, but no active exploitation or patch details are reported.

    00061616
    3.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Gitea: Three CI/CD & SSRF Flaws Fixed in 1.26.x (CVE-2026-58426, CVE-2026-22874, CVE-2026-58424) Gitea patched three issues, mostly in its Actions CI/CD. CVE-2026-58426 (9.6): an HMAC ambiguity in Actions Artifacts V4 signed URLs allows cross-repository artifact reads and cross-task upload-state writes. CVE-2026-22874 (9.6): incomplete SSRF protection in webhook and migration allow-list filtering lets an authenticated user reach internal services and metadata endpoints. CVE-2026-58424 (8.9): a permanent fork-PR workflow approval-gate bypass lets a fork PR author run CI workflows without the required maintainer approval, exposing runner secrets and resources. All three need only a low-privileged authenticated account, and their fixes are staggered across 1.26.2–1.26.4. 👉Upgrade Gitea to 1.26.4 (covers all three).

    Post summary

    The post announces that Gitea's CVE-2026-58426, CVE-2026-22874, and CVE-2026-58424 have been fixed, provides technical details, and urges users to upgrade to version 1.26.4.

    00000117
    236 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass https://www.cve.org/CVERecord?id=CVE-2026-58424 ----- Traducción: CVE-2026-58424 Puerta de aprobación del flujo de trabajo de PR de bifurcación permanente https://www.cve.org/CVERecord?id=CVE-2026-58424 Fuente: `CVEnew` `Powered… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-58424, describing a permanent Fork PR Workflow Approval Gate Bypass and linking to the CVE record, but does not provide PoC, exploit, or patch details.

    0000041
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-58424 Permanent Fork PR Workflow Approval Gate Bypass https://www.cve.org/CVERecord?id=CVE-2026-58424

    Post summary

    The post simply references a newly disclosed CVE (CVE‑2026‑58424) with a brief description and provides a link to the official CVE record.

    00000666
    57.7K followersView on X

Explore more