HTTP Artifacts V4 Backend Vulnerability in Nektos Act
CVE-2026-76847

8.7HIGH

Key Information:

Vendor

Nektos

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-76847?

The Nektos Act framework's HTTP Artifacts V4 backend is susceptible to an authorization bypass vulnerability that arises from insufficient validation of the caller-supplied workflow_run_backend_id. This oversight allows unauthorized clients visibility into, and manipulation of, artifacts without credential verification. The system's reliance on a hardcoded HMAC key for authentication exacerbates the issue, as the lack of uniqueness results in ambiguous signatures, rendering signed URLs forgeable. Additionally, the default setting for the artifact server address exposes the backend to the broader network, further compromising build outputs, including sensitive secrets and deployment credentials. As a result, attackers can read, overwrite, or delete artifacts from concurrently running jobs, facilitating potential unauthorized access and manipulation of critical workflows.

Affected Version(s)

act 0.2.81 <= 0.2.89

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Sobirov
.