CVE-2026-73802

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-03: 110-03
Referenced assets2 URLs
Full discourse1 post
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — CRITICAL GITEA ACT_RUNNER CVSS 9.9 FLAW ENABLES CI/CD RUNNER HOST TAKEOVER AND ROOT COMMAND EXECUTION October 2, 2026 DISCLOSED BY: Gitea Project Security Advisory / GitHub Security Advisory PRODUCT: Gitea act_runner — Docker-backed runners CVE: CVE-2026-73802 — CVSS 9.9 Critical AFFECTED VERSIONS: http://gitea.com/gitea/runner < 3.0.0 according to the GHSA. IMPACT: An attacker who can submit a workflow to a repository using a shared Docker-backed act_runner can supply dangerous container.options that survive even when privileged mode is disabled. This can expose host PID/IPC/mount namespaces and allow arbitrary commands to execute as root on the runner host. Successful exploitation can expose: CI/CD secrets, deployment credentials, environment variables, adjacent jobs on the same runner, and internal build infrastructure reachable from the runner host. EXPLOITATION STATUS: AUTHENTICATED / WORKFLOW-AUTHORIZED RCE — TECHNICALLY CONFIRMED PUBLIC REPRODUCTION: YES — the official advisory contains a workflow demonstrating host-namespace access and root command execution using nsenter. IN-THE-WILD EXPLOITATION: UNCONFIRMED at the time of this check. CISA KEV: Not listed in catalog version 2026.10.02. Forensic triage: Review workflow history and runner job logs for: --pid=host --ipc=host --uts=host --network=host --cap-add=ALL --cap-add=SYS_ADMIN --security-opt seccomp=unconfined --security-opt apparmor=unconfined --device --volumes-from --runtime --cgroup-parent nsenter -t 1 Also investigate unexpected root processes on runner hosts and anomalous access to deployment credentials, environment secrets or neighboring jobs. URGENT ACTION: Do not remain on an affected pre-3.0.0 act_runner deployment. Move to the current supported patched release and verify the deployed build against GHSA-x4q3-gcj3-m6cf. Until upgraded, prevent untrusted or low-trust users from creating or modifying workflows executed on shared Docker-backed runners. If suspicious workflow activity is found: isolate the runner, preserve logs, and rotate CI/CD and deployment credentials accessible from that host. SOURCE: https://github.com/go-gitea/gitea/security/advisories/GHSA-x4q3-gcj3-m6cf EXPLOITATION UPDATE: The technical description closely matches the earlier issue tracked as CVE-2026-58053. They are treated here as one underlying alert identity rather than two separate incidents. CONFIDENCE: VERY HIGH — the official project advisory documents the host-breakout path, root command execution, affected trust boundary and a reproducible attacker workflow. No trusted evidence currently supports confirmed in-the-wild exploitation or a zero-day label. #CyberSecurity #ThreatIntel #NØØT #Gitea #CICD #DevSecOps #ContainerSecurity #RCE #PrivilegeEscalation #RunnerSecurity #SupplyChainSecurity #CVE_2026_73802

    20010113
    228 followersView on X

Explore more