CVE-2026-60004

Published Aug 26, 2026

Last updated 17 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-60004 is a remote code execution (RCE) vulnerability found in Gitea, an open-source, self-hosted Git service. This code injection flaw allows an attacker with repository write access to exploit the `diffpatch` API endpoint. By sending a malicious patch, the attacker can plant an executable Git hook, which then enables them to execute arbitrary shell commands using the privileges of the Gitea service account. The vulnerability affects Gitea versions 1.17 through 1.27.0 and was addressed in version 1.27.1. The Cybersecurity and Infrastructure Security Agency (CISA) has included CVE-2026-60004 in its Known Exploited Vulnerabilities catalog, confirming its active exploitation. In configurations where open self-registration is enabled, an unauthenticated individual can obtain the necessary repository write access by simply registering an account and creating a repository.

Description
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Source
cve@mitre.org
NVD status
Analyzed
Products
gitea

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Gitea Code Injection Vulnerability
Exploit added on
Aug 25, 2026
Exploit action due
Aug 28, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

cve@mitre.org
CWE-94

Social media

Hype score
Not currently trending
  1. Vulnerabilità Gitea CVE-2026-60004: come mettere in sicur… La vulnerabilità Gitea CVE-2026-60004 richiede una verifica rapida dei server che espongono… https://t.co/yc0f9jimvY #Sicurezza #OCEWeb https://t.co/qVW8XBRIin

    @oceweb

    3 Sept 2026

    51 Impressions

    3 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Qwen asks builders for real-world workflows. We gave Qwen3.8-Flash-Next one: investigate a critical CVE end to end, fully local. It built the lab, reproduced CVE-2026-60004, verified the fix 22/22, and shipped open detections, paper and film. @Alibaba_Qwen @QwenDevs https://t.co/

    @0x00Sector

    1 Sept 2026

    80 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 🐦 🚨 CISA KEV: CVE-2026-53362 (Linux kernel) actively exploited — OpenAI's own AI agents used it to root their systems. CVE-2026-60004 (Gitea) still hits 8,300+ unpatched servers with crypto miners. ServiceNow also fixed 3x CVSS 10.0 unauth RCE/SQLi bugs. #infosec #CVE

    @ita_ipo

    31 Aug 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-60004: Gitea Remote Code Execution Bug - What It Means for Your Business and How to Respond https://t.co/xJLX3e1lbM

    @integ_sec

    30 Aug 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 𝗖𝗿𝗶𝘁𝗶𝗰𝗮𝗹 𝗚𝗶𝘁𝗲𝗮 𝗥𝗖𝗘 𝗔𝗰𝘁𝗶𝘃𝗲𝗹𝘆 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱 𝗮𝘀 𝗥𝗲𝗽𝗼𝗿𝘁𝗲𝗱 𝗔𝘁𝘁𝗮𝗰𝗸 𝗗𝗿𝗼𝗽𝘀 𝗠𝗶𝗻𝗲𝗿-𝗟𝗶𝗸𝗲 𝗣𝗮𝘆𝗹

    @ShadowSpanHQ

    30 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. GiteaのCVE-2026-60004をCISAが実悪用確認、1.27.1へ更新 https://t.co/pFvNUuypoC #IT #Security #cybersecurity

    @Teeeda_worker

    30 Aug 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🎯 Today's top exploit risk: CVE-2026-60004 (Gitea) Actively exploited. Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. #KEV #RCE #CVE

    @BytesNora

    30 Aug 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Highest live exploit risk right now — CVE-2026-60004 (Gitea) Actively exploited. Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. #CVE #RCE #SecOps

    @BytesNora

    28 Aug 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Top CVEs w/ public exploits (Aug 27): CVE-2026-60004 Vulnerability Record: CVE-2026-60004 CVE-2026-36851 Vulnerability Record: CVE-2026-36851 Protect via https://t.co/3IVcXRXJyB

    @exploitgrid

    27 Aug 2026

    31 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-60004 - EXPLOIT CVE-2026-65956 CVE-2026-77537 CVE-2026-77550 CVE-2026-77554 ..🧵👇

    @exploitgrid

    27 Aug 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. 🔒 #CyberSecurity CVE-2026-60004: Gitea Unauthenticated Remote Code Execution — Detection and Rem… "CISA has issued a warning regarding CVE-2026-60004, an unauthenticated code execution…" 🔗 https://t.co/sucOaC3222 #CyberSecurity #ThreatIntel #cve #zeroday #patchtue

    @SecurityAr58409

    27 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Legacy exposure keeps paying off for attackers. Gitea CVE-2026-60004: Patch Self-Hosted Git Before RCE Be… CISA says CVE-2026-60004 is now exploited in the wild. Gitea operators should patch, disabl… 🔗 Read → https://t.co/HYp9OqspFc

    @fynn_JourX

    27 Aug 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🛑 Gitea CVE-2026-60004: Patch Self-Hosted Git Before RCE Becomes an Incid… CISA says CVE-2026-60004 is now exploited in the wild. Gitea operators should patch, disabl… 🔗 Details → https://t.co/4x7ICRhg2y

    @lucasverdan

    27 Aug 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. For defenders, gitea cve-2026-60004: patch self-hosted git before rce becomes… should move fast. CISA says CVE-2026-60004 is now exploited in the wild. Gitea operators should patch, disabl… 🔗 Details → https://t.co/Xmubfa45RA

    @SocXAInvaders

    27 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 CVE-2026-60004 — Gitea RCE actively exploited Public PoC available, real-world attacks confirmed, and CISA has added it to KEV. Fixed in Gitea 1.27.1. https://t.co/jpZ0uos8Ge #CVE #Gitea #RCE #CyberSecurity #InfoSec #CISA https://t.co/kvRaZZz5I7

    @stem__shop

    27 Aug 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Giteaの重大な脆弱性が実際に悪用される(CVE-2026-60004) Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) #HelpNetSecurity (Aug 26) https://t.co/yPWMHEb2qA

    @foxbook

    27 Aug 2026

    230 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Heads-up: CVE-2026-60004 is under active exploitation. Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hoo… CVSS 9.8. This belongs at the top of your patch queue. https://t.co/YW4ZQtBnLJ #CVE #RCE #ActivelyExploited

    @BytesNora

    26 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004): Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known… https://t.co/WH6UtVVTt

    @shah_sheikh

    26 Aug 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🛡️ CYBER BULLETIN | 2026/08/26 🚨 CISA flags an actively exploited Gitea RCE CISA added CVE-2026-60004 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog. With default open registration, an attacker can create an account, get repo write access, plant a Git hook via

    @FrontieraTechIT

    26 Aug 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  20. 🔒 #CyberSecurity CVE-2026-60004: Gitea Code Injection Exploitation — KEV Detection and Remediati… "On August 25, 2026, CISA added CVE-2026-60004 — a code injection vulnerability in Gitea,…" 🔗 https://t.co/elMZ4jv3d8 #CyberSecurity #ThreatIntel #cve #zeroday #pat

    @SecurityAr58409

    26 Aug 2026

    35 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Gitea'da RCE Açığı Aktif Olarak İstismar Ediliyor CVE-2026-60004 kodlu uzaktan kod çalıştırma açığı CISA'nın KEV kataloğuna eklendi. Gitea kullanıcılarının 1.27.1 veya üstüne güncellemesi kritik. #CVE #SiberGüvenlik https://t.co/cmZORo9ROT

    @KubbeSiber

    26 Aug 2026

    12 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🔒 #CyberSecurity CVE-2026-60004: Gitea diffpatch Code Injection Added to CISA KEV — Detection an… "CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog on…" 🔗 https://t.co/GTwHqJgDW3 #CyberSecurity #ThreatIntel #cve202660004 #critical #cisakev

    @SecurityAr58409

    26 Aug 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🛡️ CVE-2026-60004: Vulnerabilidad Crítica de Inyección de Código en Gitea Explotada Activamente Análisis técnico de CVE-2026-60004, vulnerabilidad de inyección de código en Gitea que permite ejecutar comandos como la cuenta de servicio mediante Git hooks m https://t.c

    @CiberPlanetaOrg

    25 Aug 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 没被很多人提到,但已经被大规模利用的rce CVE-2026-60004 今早发现我的一台服务器中招了 攻击者在我的私人gitea注册了数千个帐号,启动数千个项目,通过hook实现以service用户运行挖矿程序 https://t.co/cqACBnd118

    @galaxy1025850

    16 Aug 2026

    246 Impressions

    0 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. CVE-2026-60004 - Gitea Pre-Auth Remote Code Execution https://t.co/zEluml5X0J #CVE #Gitea #RCE https://t.co/BrHNeEKJlx

    @d4rk_c0r3

    3 Aug 2026

    45 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 🚨 CVE-2026-60004 - critical 🚨 Gitea <= 1.27.0 - Pre-Auth Remote Code Execution > Gitea versions 1.17 through 1.27.0 contain a remote code execution vulnerability in t... 👾 https://t.co/RgxA7gv1Qg @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    3 Aug 2026

    56 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations