CVE-2026-59774Disclosure

MEDIUM

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

4.0/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 20 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 19 signals
  • Disclosure: 11 classified signals
  • Peaked 4d ago at 5 mentions (2026-08-06); latest day: 3
  • 20 total mentions across 7 days

Deep dive

Activity timeline20 mentions / 7d
01345Mentions · 2026-08-04: 4Mentions · 2026-08-05: 2Mentions · 2026-08-06: 5Mentions · 2026-08-07: 1Mentions · 2026-08-10: 2Mentions · 2026-08-12: 3Mentions · 2026-08-13: 3Active Exploitation · 2026-08-06: 1Patch / Workaround · 2026-08-04: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-06: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-12: 3Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-04: 4Technical Details · 2026-08-05: 2Technical Details · 2026-08-06: 5Technical Details · 2026-08-07: 1Technical Details · 2026-08-10: 2Technical Details · 2026-08-12: 3Technical Details · 2026-08-13: 208-0408-0508-0608-0708-1008-1208-13
Signal classification4 categories
Disclosure
1155.0%
Patch
735.0%
Active Exploitation
15.0%
General
15.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-08-044
Disclosure3Patch1
2026-08-052
Disclosure1Patch1
2026-08-065
Active Exploitation1Disclosure3Patch1
2026-08-071
Patch1
2026-08-102
Disclosure2
2026-08-123
Disclosure1Patch2
2026-08-133
Disclosure1General1Patch1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    - No login - No write access - Just crafted Org-mode markup 🛑 CVE-2026-59774, a critical Gitea flaw, lets attackers use a public repository to read any file accessible to the Gitea service account. Gitea says it could also be chained into command execution. How it works and what admins should check: https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html

    Post summary

    The post announces a critical CVE-2026-59774 affecting Gitea, describing how an unauthenticated attacker can read arbitrary files and possibly chain to command execution, without providing PoC or patch details.

    845526810969.7K
    2.3M followersView on X
  • Shai rod@NightRang3r
    Disclosure

    The Gitea File Inclusion vulnerability I independently reported has now been publicly disclosed as CVE-2026-59774. The issue was also discovered and reported by XBOW. An unauthenticated attacker could abuse Gitea’s Org-mode rendering to read arbitrary files accessible to the Gitea OS user, including configuration files containing internal tokens, secrets, and database credentials. By extracting Gitea’s INTERNAL_TOKEN, the vulnerability could be escalated to remote code execution as the Gitea OS user. Full advisory: https://github.com/go-gitea/gitea/security/advisories/GHSA-6v53-hr58-556r

    Post summary

    A public disclosure (CVE-2026-59774) of a Gitea file inclusion flaw that enables unauthenticated file reads and could lead to remote code execution via INTERNAL_TOKEN extraction.

    19053173.9K
    1.1K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidad crítica de lectura de archivos en Gitea permite ejecución remota de código Se ha detectado una vulnerabilidad de seguridad crítica en Gitea (CVE-2026-59774) que permite a atacantes remotos no autenticados leer archivos https://blog.elhacker.net/2026/08/vulnerabilidad-critica-de-lectura-de.html

    Post summary

    A new critical vulnerability (CVE‑2026‑59774) in Gitea allows unauthenticated attackers to read files and remotely execute code; the announcement reports the flaw but gives no details on PoC, exploits, or patches.

    0701944.7K
    141.7K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Patch

    یک آسیب‌پذیری بحرانی در پلتفرم گیت‌هاست خودمیزبان Gitea کشف شده است که نسخه‌های ۱.۲۲.۱ تا ۱.۲۷.۰ را تحت تأثیر قرار می‌دهد. این نقص با شناسه CVE-2026-59774 ردیابی شده، امتیاز CVSS 9.8 دریافت کرده و به مهاجم احراز هویت‌نشده اجازه می‌دهد بدون نیاز به ورود به سیستم یا دسترسی نوشتاری، هر فایلی را که حساب سرویس Gitea به آن دسترسی دارد بخواند. تنها پیش‌نیاز حمله، وجود یک مخزن (repository) عمومی و ارسال نشانه‌گذاری Org-mode دستکاری‌شده به نقطه پایانی رندرینگ است. این آسیب‌پذیری توسط سیستم امنیت تهاجمی خودکار XBOW Security کشف شد و در نسخه Gitea 1.27.1 که باید فوراً نصب شود، رفع گردیده است. نمونه‌های ابری به‌صورت خودکار به‌روزرسانی می‌شوند.

    Post summary

    Critical unauthenticated file‑read vulnerability (CVE‑2026‑59774) affects Gitea 1.22.1–1.27.0; the issue is fixed in 1.27.1, which should be applied immediately.

    000110670
    19.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-59774 - critical 🚨 Gitea 1.22.1-1.27.0 - Unauthenticated Arbitrary File Read > Gitea versions 1.22.1 through 1.27.0 initialize the go-org markup renderer without re... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-59774 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces a critical unauthenticated arbitrary file read vulnerability in Gitea 1.22.1–1.27.0, offering version details and a link to a library, but does not provide exploit code, active use, or patch information.

    00023372
    1.2K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    A critical Gitea vulnerability, CVE-2026-59774, lets unauthenticated attackers read server files and reach remote code execution. #Gitea #CVE202659774 #RCE #RemoteCodeExecution #ArbitraryFileRead #Vulnerability #PathTraversal #InfoSec #CyberSecurity https://securityonline.info/gitea-vulnerability-cve-2026-59774/ https://t.co/jN4WaYqva4

    Post summary

    The tweet discloses a new critical Gitea vulnerability (CVE-2026-59774) that permits unauthenticated file reads and remote code execution.

    03020528
    12.9K followersView on X
  • Nicolas Cantu ou pas@NicolasCantuBk
    General

    @Lab312_ @PierreNoizat 13/08 06:09 sur /api/internal/manager/*. exploitation de la CVE-2026-59774

    Post summary

    The tweet notes that CVE‑2026‑59774 is being exploited via /api/internal/manager/ but gives no further technical or attack‑related details.

    1000087
    1.5K followersView on X
  • Stanislav Klevtsov@stansecure
    Patch

    Top #CVE to #patch this week 👀 - @VMware #ESXi 9.0 RCE (CVE-2026-47876, CVE-2026-41703) - @JetBrains #TeamCity RCE (CVE-2026-63077, CVE-2026-65907) - #Jenkins Core (CVE-2026-70426) - @zohocorp ManageEngine ADAudit RCE (CVE-2026-6516) - @IBM Langflow RCE (CVE-2026-9198) - @ApacheKylin OS command injection (CVE-2026-62392) - #MOVEit auth bypass (CVE-2026-4670) - @giteaio unauth file read (CVE-2026-59774)

    Post summary

    The tweet highlights a list of recent CVEs requiring patches, providing brief technical descriptors (RCE, command injection, etc.), without mentioning exploit code, active attacks, or false‑positive claims.

    1000073
    44 followersView on X
  • Criminal IP@CriminalIP_US
    Patch

    🍵 Gitea CVE-2026-59774 vulnerability analysis CVE-2026-59774 is a critical path traversal vulnerability affecting Gitea, allowing unauthenticated attackers to read arbitrary files from the server. If a public repository with Code Units enabled exists, attackers can abuse crafted Org-mode markup to access files readable by the Gitea service account. 🔎 Criminal IP findings: • More than 10,000 Internet-exposed Gitea instances were identified via title: Gitea • Approximately 16,000 assets were identified through html_meta_keywords: "gitea" • Exposed Gitea version information can be used to identify assets potentially affected by versions 1.22.1–1.27.0 Organizations should upgrade to Gitea 1.27.1 or later, review anonymous markup requests, and rotate internal tokens, OAuth/JWT secrets, and database credentials if exposure is suspected. 👉Read the full analysis: https://www.criminalip.io/knowledge-hub/blog/37073 #Gitea #CVE202659774 #PathTraversal #ThreatIntelligence #Cybersecurity

    Post summary

    CVE‑2026‑59774 is a path‑traversal vulnerability in Gitea that lets unauthenticated attackers read arbitrary server files via crafted Org‑mode markup; the recommended mitigation is to upgrade to Gitea 1.27.1 or later and secure internal credentials.

    01000276
    4.9K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Gitea の深刻な脆弱性 CVE-2026-59774 が FIX::サーバー上のファイル読み取りとコード実行の恐れ https://iototsecnews.jp/2026/08/04/critical-gitea-flaw-lets-unauthenticated-attackers-read-server-files-and-execute-code/ オープンソースのソフトウェア開発プラットフォームである Gitea において、外部からの不正操作を可能にする重大な不具合が特定されました。外部の第三者が認証を経ずにサーバー内部の重要なファイルを直接閲覧でき、そこからシステム全体を管理する権限を奪取される危険性があります。組織の機密情報や重要な設定データが外部へ漏洩するだけでなく、不正なプログラムが実行される恐れがあるため注意が必要です。この問題 CVE-2026-59774 (GHSA-6v53-hr58-556r) の対策として、開発元が配信している修正済みバージョン v1.27.1 以降へ迅速に更新してください。ご利用のチームは、ご注意ください。 #Gitea #CVE202659774 #Vulnerability #Repository #OpenSource #RCE

    Post summary

    The article reports a critical Gitea vulnerability (CVE-2026-59774) that lets unauthenticated attackers read sensitive server files and possibly execute code. Users are urged to update to v1.27.1 or newer to mitigate the flaw.

    01000295
    507 followersView on X
  • Scripted World@Milwyn1
    Active Exploitation

    Critical Gitea zero-day CVE-2026-59774 active exploitation unauthenticated attackers reading arbitrary server files remote code execution confirmed. Path traversal Org-mode markup renderer go-org versions v1.22.1 through v1.27.0 vulnerable. Attackers submit crafted INCLUDE directive /markup endpoint public repository exfiltrate app.ini internal tokens OAuth secrets. INTERNAL_TOKEN injection malicious Git hooks enables command execution Gitea OS user anonymous clone. Zero authentication write access required public repository code unit enabled sufficient. #Gitea #CVE #RCE #ActiveExploit

    Post summary

    CVE‑2026‑59774 in Gitea is actively exploited with unauthenticated remote code execution via Org‑mode path traversal, permitting attackers to read server files and inject malicious Git hooks. No patch or mitigation is mentioned.

    0001093
    1.1K followersView on X
  • CyberTLDR@CyberTLDR
    Disclosure

    1/3 An unauthenticated attacker can read any file your Gitea service account can touch. CVE-2026-59774 (CVSS 9.8) hits versions 1.22.1 to 1.27.0. No login, no repo write, just a public repo and crafted Org-mode markup. Patched? #CyberSecurity #InfoSec #CVE #DevOps https://t.co/iL7DiADHRR

    Post summary

    The tweet announces CVE-2026-59774, a high-severity unauthenticated file-read flaw in Gitea (versions 1.22.1‑1.27.0) that can be exploited via crafted Org-mode markup without requiring a login or repo write, and asks whether the issue has been patched.

    1000063
    40 followersView on X
  • Xavier Rivera@XavierRiveraX
    Patch

    Gitea, the self-hosted Git platform, patched a critical unauthenticated file-read bug (CVE-2026-59774, CVSS 9.8) in versions 1.22.1 through 1.27.0. A crafted Org-mode #+INCLUDE directive on any public repo let attackers pull files the service account can read, no login needed. Self-hosted admins should upgrade to 1.27.1 now and rotate internal tokens if the markup endpoint shows anonymous hits.

    Post summary

    Gitea issued a patch for CVE-2026-59774 – a critical unauthenticated file‑read flaw – and advises self‑hosted admins to upgrade to 1.27.1 immediately and rotate tokens.

    0001098
    596 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🛡️ A critical Gitea flaw (CVE-2026-59774) lets unauthenticated attackers read sensitive server files and could lead to remote code execution. Publicly accessible Gitea instances are especially at risk. Update to v1.27.1 now. #CyberSecurity #Gitea Read more: https://thecyberedition.com/critical-gitea-cve-2026-59774-flaw-enables-arbitrary-file-read-and-remote-code-execution/

    Post summary

    A critical Gitea flaw (CVE‑2026‑59774) enables unauthenticated reading of server files and may lead to remote code execution; all publicly accessible instances should update to v1.27.1 immediately.

    00010122
    741 followersView on X
  • Criminal IP Japan@CriminalIP_JP
    Disclosure

    🍵ログインなしでサーバーファイルを読み取るGitea脆弱性​ セルフホスト型Gitプラットフォーム15において、認証なしでサーバー上の任意ファイルを読み取れる「CVE-2026-59774」が公開されました。​ CVSS v3.1は9.8(Critical)。公開リポジトリが1つ存在し、コードユニットが有効化されている場合、攻撃者はログインや書き込み権限なしで、Giteaサービスアカウントが読み取れるファイルにアクセスできる可能性があります。​ 🔎 Criminal IP IT資産検索で確認したポイント​ ・title: Giteaで10,000件以上の関連インスタンスを検出​ ・html_meta_keywords: "gitea"で約16,000件の結果を確認​ ・Powered by Giteaキーワードからバージョン情報が露出している資産を確認​ 攻撃者により、app.iniが読み取られた場合、INTERNAL_TOKEN、OAuth・JWT関連のシークレット、データベース認証情報などが漏えいし、リモートコード実行へと連鎖するおそれがあります。​ Giteaを運用している場合は、1.27.1以上へのアップグレードと、漏えいが疑われる認証情報のローテーションを実施する必要があります。​ 🔗詳細はこちら​ https://www.criminalip.io/ja/knowledge-hub/blog/9805​ #Gitea #CVE #脆弱性 #サイバーセキュリティ #ASM

    Post summary

    The post announces a critical CVE‑2026‑59774 vulnerability in Gitea that allows unauthenticated server file reading, highlights potential for remote code execution if sensitive files are accessed, and urges users to upgrade to version 1.27.1 or later.

    00000338
    1.4K followersView on X
  • Carlos Fynn@fynn_JourX
    Disclosure

    Legacy exposure keeps paying off for attackers. Gitea Org-mode flaw turns public repositories into a serv… CVE-2026-59774 lets unauthenticated attackers use crafted Org-mode markup in public Gitea r… 🔗 Read → https://invaders.ie/resources/blog/vulnerability/gitea-org-mode-flaw-turns-public-repositories-into-a-server-file-read-risk

    Post summary

    A new Gitea Org‑mode flaw (CVE‑2026‑59774) allows unauthenticated attackers to craft Org‑mode markup that reads files from public repositories, with no PoC, exploit code, or patch referenced yet.

    0000040
    86 followersView on X
  • Lucas@lucasverdan
    Disclosure

    🛑 Gitea Org-mode flaw turns public repositories into a server file-read r… CVE-2026-59774 lets unauthenticated attackers use crafted Org-mode markup in public Gitea r… 🔗 Details → https://invaders.ie/resources/blog/vulnerability/gitea-org-mode-flaw-turns-public-repositories-into-a-server-file-read-risk

    Post summary

    The tweet discloses that CVE‑2026‑59774 permits unauthenticated file‑read attacks on public Gitea repositories via crafted Org‑mode markup.

    0000058
    308 followersView on X
  • Techsico IT@Techsico_IT
    Patch

    Gitea admins: CVE-2026-59774 is critical (CVSS 9.8). Unauthenticated path traversal can expose files and lead to RCE. Affected: 1.22.1–1.27.0. Patch to 1.27.1+ NOW. https://t.co/PAo9dtYplZ

    Post summary

    The tweet alerts Gitea admins to a critical CVE‑2026‑59774 causing unauthenticated path traversal leading to RCE, and urges immediate patch to version 1.27.1+.

    0000038
    6 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    Disclosure

    Gitea Vulnerability Enables Remote Code Execution (CVE-2026-59774) http://dlvr.it/TTtfn4 #patchmanagement

    Post summary

    The tweet announces a newly disclosed Gitea vulnerability (CVE-2026-59774) that allows remote code execution, but provides no proof‑of‑concept, exploit details, or patch information.

    0000058
    2.0K followersView on X
  • NeoTeo.com@NeoteoCom
    Disclosure

    CVE-2026-59774 en Gitea: sin login y con solo markup Org-mode en un repo público, un atacante lee cualquier archivo del servidor. Gitea confirma que puede encadenarse a command execution: https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html

    Post summary

    The CVE‑2026‑59774 flaw in Gitea allows unauthenticated file reads via Org‑mode markup in public repositories and can potentially be chained to command execution; no exploit, patch, or active exploitation is reported.

    00000144
    15.9K followersView on X

Explore more