CVE-2026-67308Disclosure

MEDIUM

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

5.5/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-08-01); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-08-01: 4Mentions · 2026-08-02: 2Mentions · 2026-08-03: 1PoC Mentioned / Linked · 2026-08-03: 1Active Exploitation · 2026-08-01: 1Active Exploitation · 2026-08-02: 1Patch / Workaround · 2026-08-01: 2Patch / Workaround · 2026-08-03: 1Technical Details · 2026-08-01: 3Technical Details · 2026-08-02: 1Technical Details · 2026-08-03: 108-0108-0208-03
Signal classification4 categories
Disclosure
342.9%
Active Exploitation
228.6%
General
114.3%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-014
Active Exploitation1Disclosure2General1
2026-08-022
Active Exploitation1Disclosure1
2026-08-031
Patch1
Full discourse7 posts
  • SecAlerts@SecAlertsCo
    Active Exploitation

    🍴 Wazuh GitHub Actions hit with CVSS 10 shell injection - CVE-2026-67308. Attackers fork the repo, craft a malicious VERSION.json in a PR, and execute arbitrary OS commands in CI. Update to commit 44bf114+. #cybersecurity #ciso #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-67308?utm_campaign=x https://t.co/9zes6zNvsm

    Post summary

    CVE-2026-67308 allows shell injection via a malicious VERSION.json in GitHub Actions, is actively being exploited in the wild, and has been patched in commit 44bf114+.

    01010268
    871 followersView on X
  • Sami Laiho@samilaiho
    Patch

    Wazuh GitHub Actions Shell Injection via Fork Pull Request URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67308 Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 10.0

    Post summary

    CVE-2026-67308 is a critical shell injection flaw in Wazuh GitHub Actions with an official fix available and PoC-level exploitation demonstrated, rated CVSS 10.0.

    01000992
    30.6K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting Wazuh Workflows (CVE-2026-67308) https://vuldb.com/vuln/385268/cti

    Post summary

    The brief alert indicates that elevated activity has been detected targeting the Wazuh Workflows CVE-2026-67308, suggesting that the vulnerability is currently being used in active attacks.

    00000111
    2.3K followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐 🚨 Wazuh GitHub Actions RCE — CVSS 10.0 CVE-2026-67308: Shell injection via crafted VERSION.json in fork pull requests → CI/CD pipeline takeover. Update to commit 44bf114 NOW. → http://threataft.com/articles/wazuh-github-actions-cve-2026-67308 #cybersecurity #infosec #Wazuh #GitHubActions #CICD #ThreatIntel

    Post summary

    A new CVE (CVE-2026-67308) is disclosed with detailed exploitation method and CVSS rating, but no PoC, tool, or active exploitation evidence is provided.

    0000061
    36 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Wazuh Workflows (CVE-2026-67308) https://vuldb.com/vuln/385268

    Post summary

    A severe vulnerability (CVE-2026-67308) has been disclosed for Wazuh Workflows, with a reference to a VulDB entry, but no PoC, exploitation details, patches, or technical specifics are mentioned.

    00000134
    2.3K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Wazuh GitHub Actions Shell Injection via VERSION.json (CVE-2026-67308) Wazuh workflows before 44bf114 parse VERSION.json from PRs and export values into env vars that are interpolated in GitHub Actions run: steps. Shell metacharacters in VERSION.json break out into arbitrary command execution, enabling secret exfil (GITHUB_TOKEN/AWS creds) especially on self-hosted runners. 👉Affected: wazuh workflows < 44bf114 | Upgrade to 44bf114

    Post summary

    The tweet discloses a critical shell injection flaw in Wazuh GitHub Actions that permits arbitrary command execution and secret exfiltration; upgrading to commit 44bf114 resolves the issue.

    00000149
    278 followersView on X
  • Xavier Rivera@XavierRiveraX
    General

    NVD assigned CVE-2026-67308 (CVSS 10.0) to a shell injection flaw in Wazuh's GitHub Actions workflows. A crafted VERSION.json in a pull request lets attackers run arbitrary commands and exfiltrate GITHUB_TOKEN plus AWS credentials from self-hosted runners. https://thecircuitry.to/article/nvd-adds-shell-injection-flaw-in-wazuh-github-actions-workflows-as-cve-2026-6730-msaev55r

    Post summary

    The NVD has assigned CVE-2026-67308 as a shell injection flaw in Wazuh GitHub Actions that allows arbitrary command execution via a crafted VERSION.json, but the post provides no evidence of exploitation or remediation.

    00000125
    597 followersView on X

Explore more