Skip to content

Security7 publishers2 min readPublished Updated

Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers

Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers
Generated illustration

What happened

  • Shadowserver counted 8,393 internet-facing Gitea IPs still vulnerable to CVE-2026-60004 on August 27 and said the exposed servers remain under active attack.
  • The flaw is a code injection in Gitea's diffpatch API endpoint that runs arbitrary shell commands with the privileges of the Gitea service account.
  • Gitea released version 1.27.1 on July 27 to close the hole and told operators to upgrade their servers as soon as possible.
  • CISA added the CVE to its exploited-flaws catalog on Tuesday and gave Federal Civilian Executive Branch agencies three days to patch, to August 28, under BOD 26-04.
  • Reported in-the-wild exploitation has attackers installing cryptocurrency mining malware on unpatched Gitea servers, with CISA yet to publish attack details.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Any Gitea instance that kept the shipped registration default is reachable by whoever can load its signup page, which means anyone who finds that page can meet the write-access precondition.
  • decision Version tracking no longer settles whether an instance is safe; operators have to decide who may create accounts and repositories on a self-hosted code server at all.
  • capability Command execution as the Gitea service account puts an attacker on the machine that stores and serves the repositories, which is the position needed to alter what developers pull.
  • precedent Two separate routes into self-hosted Gitea have been abused within two months, so the surface being worked is the platform rather than this one endpoint.

The chain runs from a public signup form to a shell in four steps. An attacker loads the registration page on any instance that kept the shipped default [5], creates an account, creates a repository, and thereby holds the ordinary write access the bug requires [4]. Then a patch goes to the diffpatch endpoint. Gitea's security team says that endpoint can be abused to install and execute a Git hook from repository-controlled content, and the hook runs shell commands as the Gitea OS user [6].

Gitea shipped 1.27.1 on July 27 for the flaw, which Salesforce security researcher Shai Rod reported [7][3]. Shadowserver's vulnerable count is dated August 27 [1]. That is 31 days of patch availability measured against 8,393 hosts still answering [1]. CISA's deadline for Federal Civilian Executive Branch agencies is August 28, one day after that scan, and the three-day window comes from BOD 26-04, which binds federal civilian agencies and nobody else [2][9]. The other operators in the 8,393 have no such deadline.

Gitea reports more than 400,000 installations [12]. The vulnerable figure is roughly 2 percent of that [3], but the two numbers are not the same measurement: Shadowserver counts internet-facing IPs that answer a scan [1]. An install behind a VPN with signup disabled never enters the population, so read 8,393 as exposed-and-vulnerable, not as a share of the fleet.

The advisory language says authenticated [2]. On a default install that qualifier describes nothing useful about who can reach the endpoint [5]. It does still matter on a locked-down instance, where the precondition is ordinary write access to any repository on the box [6], the level a contractor account or a stale integration token already has.

This is the second route into self-hosted Gitea worked in two months. In July, threat actors were seen abusing CVE-2026-20896, an authentication bypass in the official Gitea Docker image affecting instances with reverse proxy authentication headers enabled [11]. The payload reported on CVE-2026-60004 so far is cryptocurrency mining malware [10], installed by whichever attackers got there first; that says nothing about the ceiling on command execution as the account that serves the repositories.

Exposure here has two variables: the version the box runs, and whether a stranger can still create an account on it. A patch report shows only the first.

What to watch

  • Whether Shadowserver's vulnerable count falls after the August 28 federal deadline, and by how much.
  • Whether any payload beyond cryptocurrency mining appears: repository tampering or credential theft on a compromised Gitea host would reprice this.
  • Whether Gitea changes the shipped self-registration default in a follow-up release.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories