Black & White Path
Aug 6, 2026 · Information Security
Critical Gitea CVE-2026-59774 (CVSS 9.8) Enables Unauthenticated File Read
A newly disclosed Gitea vulnerability (CVE‑2026‑59774) lets unauthenticated attackers read any file accessible to the service account via a crafted Org‑mode markup request, affects versions 1.22.1‑1.27.0, can be chained to remote code execution, and is fixed in 1.27.1.
CVE-2026-59774GiteaMITRE ATT&CK
0 likes · 10 min read
