Critical Remote Code Execution in Gitea (CVE‑2026‑60004) Added to CISA KEV Catalog
What It Is — Gitea is an open‑source self‑hosted Git service. CVE‑2026‑60004 is a critical remote‑code‑execution flaw (CVSS 9.8) that allows an attacker with write access to a repository to execute arbitrary shell commands as the Gitea service user. Because Gitea enables open registration by default, an unauthenticated attacker can create an account, a repository, and exploit the vulnerable diff‑patch API to plant malicious Git hooks.
Exploitability — The vulnerability is publicly disclosed and has been observed in the wild (cryptocurrency‑miner payload). No separate proof‑of‑concept is required; exploitation follows the unauthenticated account‑creation path.
Affected Products — Gitea versions 1.17 through 1.27.0. The issue is patched in version 1.27.1.
Why It Matters for Compliance & Audit Readiness
- Highlights the need for continuous monitoring and timely patching of open‑source components to satisfy SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations).
- Underscores the importance of strict user‑provisioning controls (disabling default open registration) as evidence for SOC 2 CC6.2 (User Management).
- Provides concrete remediation artifacts (patch version, configuration changes, log excerpts) that can be presented in a SOC 2 audit to demonstrate due diligence.
Recommended Actions
- Upgrade all Gitea instances to ≥ 1.27.1 without delay.
- Disable open registration; enforce MFA and least‑privilege role assignments for new users.
- Deploy continuous vulnerability scanning and automated patch management for all open‑source services.
- Capture and retain remediation evidence (patch logs, configuration snapshots, audit trails) for SOC 2 audit readiness.
Source: SecurityAffairs article