Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-26 ยท updated: 2026-08-26 ยท tags: [cve, kev, gitea, git, code-injection, devops, supply-chain] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government] ยท au_impact: true

CVE-2026-60004

CVE-2026-60004 is a code-injection vulnerability in the Gitea self-hosted Git service that allows attackers to execute arbitrary code on vulnerable servers. On 25 August 2026, CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild.

Vulnerability Details

Attribute Detail
CVE CVE-2026-60004
Product Gitea (Self-hosted Git service)
Type Code injection
KEV Status Added to CISA KEV on 2026-08-25 (BOD 26-04)
Exploitation Status Actively exploited in the wild

Context & Impact

Gitea is widely deployed across small development teams, internal DevOps toolchains, and enterprise self-hosted environments. The inclusion in CISA's KEV Catalog requires US Federal Civilian Executive Branch (FCEB) agencies to remediate within established BOD 26-04 deadlines and assess systems for potential pre-patch compromise. The vulnerability presents significant supply chain and code integrity risks for any engineering organisation operating self-hosted Gitea instances.

Remediation

Organisations running self-hosted Gitea instances should: 1. Update Gitea installations immediately to the latest patched release. 2. Review server logs and Git repository commit histories for signs of unauthorised access or pre-patch exploitation. 3. Restrict administrative interfaces and repository management endpoints behind zero-trust access controls or corporate VPNs.

Australian Context

Development teams and government entities across Australia leveraging open-source and self-hosted version control infrastructure like Gitea should review their exposure and ensure patching compliance aligns with ACSC Essential Eight mitigation strategies regarding application control and rapid patching.

Sources