What is CVE-2026-59774?
A critical flaw in Gitea allows an unauthenticated attacker to read any server file accessible to the service account. The attacker only needs a public repository and crafted Org-mode markup, requiring no login or write access. Affected versions 1.22.1 through 1.27.0 must be immediately upgraded to version 1.27.1.
Azərbaycanca: Gitea platformasında kritik boşluq autentifikasiya olunmamış şəxsə xidmət hesabının əldə edə biləcəyi istənilən server faylını oxumağa imkan verir. Təcavüzkar üçün açıq depo və xüsusi hazırlanmış Org-mode işarələməsi kifayətdir, giriş və ya yazma icazəsi tələb olunmur. Təsirlənən 1.22.1 - 1.27.0 versiyaları dərhal 1.27.1 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Does exploiting CVE-2026-59774 require an attacker to have an account or special permissions on Gitea?
No, any unauthenticated person can exploit this flaw. The attacker only needs a public repository and crafted Org-mode markup, requiring no login or write access.
Which versions of Gitea are affected by CVE-2026-59774 and how to mitigate it?
Versions 1.22.1 through 1.27.0 are affected. To mitigate, you must immediately upgrade to version 1.27.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.