# CVE-2026-27771: Gitea - Authentication Bypass

> Live exploitation tracking for CVE-2026-27771 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-27771

## Key facts

- **Exploitation phase:** Active Exploitation. The vulnerability is actively exploited at scale across the internet, often via automated tools and large attack campaigns.
- **Public exploit available:** Yes
- **Affected products:** Gitea
- **Weaknesses:** CWE-306 (Missing Authentication for Critical Function)
- **Tags:** scm

## Description

Gitea contains a high-severity authentication bypass vulnerability affecting the built-in container and package registry functionality. CVE-2026-27771 allows unauthenticated remote attackers to retrieve private container images and package artifacts without valid credentials due to missing access control enforcement in OCI-backed registry requests. The vulnerability impacts self-hosted Gitea deployments prior to version 1.26.2 and is particularly dangerous for organizations storing proprietary code, internal dependencies, credentials, or build artifacts within private registries.

## CrowdSec analysis

[CVE-2026-27771](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-27771) is a newly identified vulnerability, but specific details regarding its nature, affected components, and potential impact have not yet been disclosed. As information becomes available, organizations should monitor official advisories to assess risk and determine appropriate mitigation steps.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec network data shows that most actors exploiting CVE-2026-27771 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature.
Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2026-27771. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit the `/v2/token` endpoint to obtain unauthorized tokens and then access `/v2/_catalog` to enumerate and pull private container images from vulnerable Gitea instances. This allows unauthenticated users to bypass access controls and exfiltrate sensitive data from private registries.

## Timeline

- 2026-05-28: CVE Published. CVE-2026-27771 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2026-27771 exploitation attempts against the CrowdSec Network.
- 2026-06-25: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-27771 for the first time.

## References

- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-27771.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-27771) follows observed exploitation activity for CVE-2026-27771. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
