Security7 publishers2 min readPublished Updated
Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers
Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Shadowserver counted 8,393 internet-facing Gitea IPs still vulnerable to CVE-2026-60004 on August 27 and said the exposed servers remain under active attack.
- The flaw is a code injection in Gitea's diffpatch API endpoint that runs arbitrary shell commands with the privileges of the Gitea service account.
- Gitea released version 1.27.1 on July 27 to close the hole and told operators to upgrade their servers as soon as possible.
- CISA added the CVE to its exploited-flaws catalog on Tuesday and gave Federal Civilian Executive Branch agencies three days to patch, to August 28, under BOD 26-04.
- Reported in-the-wild exploitation has attackers installing cryptocurrency mining malware on unpatched Gitea servers, with CISA yet to publish attack details.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Any Gitea instance that kept the shipped registration default is reachable by whoever can load its signup page, which means anyone who finds that page can meet the write-access precondition.
- decision Version tracking no longer settles whether an instance is safe; operators have to decide who may create accounts and repositories on a self-hosted code server at all.
- capability Command execution as the Gitea service account puts an attacker on the machine that stores and serves the repositories, which is the position needed to alter what developers pull.
- precedent Two separate routes into self-hosted Gitea have been abused within two months, so the surface being worked is the platform rather than this one endpoint.
The chain runs from a public signup form to a shell in four steps. An attacker loads the registration page on any instance that kept the shipped default [5], creates an account, creates a repository, and thereby holds the ordinary write access the bug requires [4]. Then a patch goes to the diffpatch endpoint. Gitea's security team says that endpoint can be abused to install and execute a Git hook from repository-controlled content, and the hook runs shell commands as the Gitea OS user [6].
Gitea shipped 1.27.1 on July 27 for the flaw, which Salesforce security researcher Shai Rod reported [7][3]. Shadowserver's vulnerable count is dated August 27 [1]. That is 31 days of patch availability measured against 8,393 hosts still answering [1]. CISA's deadline for Federal Civilian Executive Branch agencies is August 28, one day after that scan, and the three-day window comes from BOD 26-04, which binds federal civilian agencies and nobody else [2][9]. The other operators in the 8,393 have no such deadline.
Gitea reports more than 400,000 installations [12]. The vulnerable figure is roughly 2 percent of that [3], but the two numbers are not the same measurement: Shadowserver counts internet-facing IPs that answer a scan [1]. An install behind a VPN with signup disabled never enters the population, so read 8,393 as exposed-and-vulnerable, not as a share of the fleet.
The advisory language says authenticated [2]. On a default install that qualifier describes nothing useful about who can reach the endpoint [5]. It does still matter on a locked-down instance, where the precondition is ordinary write access to any repository on the box [6], the level a contractor account or a stale integration token already has.
This is the second route into self-hosted Gitea worked in two months. In July, threat actors were seen abusing CVE-2026-20896, an authentication bypass in the official Gitea Docker image affecting instances with reverse proxy authentication headers enabled [11]. The payload reported on CVE-2026-60004 so far is cryptocurrency mining malware [10], installed by whichever attackers got there first; that says nothing about the ceiling on command execution as the account that serves the repositories.
Exposure here has two variables: the version the box runs, and whether a stranger can still create an account on it. A patch report shows only the first.
What to watch
- Whether Shadowserver's vulnerable count falls after the August 28 federal deadline, and by how much.
- Whether any payload beyond cryptocurrency mining appears: repository tampering or credential theft on a compromised Gitea host would reprice this.
- Whether Gitea changes the shipped self-registration default in a follow-up release.