CVE-2026-34042Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache server listens to connections on all interfaces and allows anyone who can connect to it including someone anywhere on the internet to create caches with arbitrary keys and retrieve all existing caches. If they can predict which cache keys will be used by local actions, they can create malicious caches containing whatever files they please most likely allowing arbitrary remote code execution within the docker container. This issue has been patched in version 0.2.86.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-31: 3Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 203-31
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-34042 📊 Severity: 8.2 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34042 #CVE-2026-34042 #CVE #High #CyberSecurity #InfoSec https://t.co/EtAZDzB92U

    Post summary

    A new high‑severity CVE (CVE‑2026‑34042) has been announced, but no additional technical, exploit, or mitigation details are disclosed.

    0000025
    123 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-34042 act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache server listens to connections on all interfac… https://www.cve.org/CVERecord?id=CVE-2026-34042

    Post summary

    The CVE highlights that act versions older than 0.2.86 expose a server listening on all interfaces; updating to 0.2.86 fixes the issue.

    0000098
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34042 - High act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache server listens to connections on all interfaces and allows anyone who ... https://www.thehackerwire.com/vulnerability/CVE-2026-34042/ https://t.co/xH5cPQ5zbc

    Post summary

    The post announces CVE-2026-34042 as a high‑severity flaw in the act project, noting that its cache server unintentionally listens on all interfaces, potentially exposing it to unauthorized access. No exploit code, patch, or active exploitation details are provided.

    0000047
    163 followersView on X

Explore more