CVE-2026-76847Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and never check that it belongs to the requester: validateRunIDV4 in pkg/artifacts/artifacts_v4.go parses the value and returns it with the comparison against the requesting task's run ID left commented out. The signed URLs the backend issues are authenticated by an HMAC whose key is hardcoded to the four bytes 0xba 0xdb 0xee 0xf0, identical in every build, computed over a concatenation of endpoint, expiry, artifact name and task ID with no length prefix or delimiter, so signatures are both forgeable and ambiguous between differing artifact name and task ID pairs. The --artifact-server-addr flag defaults to the host's outbound address rather than loopback, leaving the backend reachable from the surrounding network. Any client that can reach it may read, overwrite or delete the artifacts of a concurrently running job with no credentials, exposing build outputs such as secrets and deployment credentials and permitting their replacement before the owning job consumes them.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-25: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-25: 108-25
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - act Artifacts V4 backend missing authorization and hardcoded HMAC key enables artifact takeover (CVE-2026-76847) nektos/act runs an HTTP Artifacts V4 backend for actions/*-artifact@v4 whose RPCs accept a caller-supplied workflow_run_backend_id with no ownership check (validateRunIDV4), and signs URLs with the hardcoded HMAC key 0xbadbeef0 over ambiguous input. When --artifact-server-addr is set to a non-loopback address, adjacent network clients can forge signatures and read, overwrite, or delete artifacts from any run. 👉Affected: nektos/act 0.2.81–0.2.89 | No fix yet — bind the artifact server to loopback and avoid actions/upload-artifact@v4 / download-artifact@v4 under act until patched

    Post summary

    The CVE-2026-76847 finds that nektos/act’s Artifacts V4 backend lacks authorization checks, using a hardcoded HMAC key that lets attackers take over artifacts; no fix yet but users should restrict the server to loopback and avoid artifact actions until patched.

    0000060
    294 followersView on X

Explore more