HTTP Artifacts V4 Backend Vulnerability in Nektos Act
CVE-2026-76847
What is CVE-2026-76847?
The Nektos Act framework's HTTP Artifacts V4 backend is susceptible to an authorization bypass vulnerability that arises from insufficient validation of the caller-supplied workflow_run_backend_id. This oversight allows unauthorized clients visibility into, and manipulation of, artifacts without credential verification. The system's reliance on a hardcoded HMAC key for authentication exacerbates the issue, as the lack of uniqueness results in ambiguous signatures, rendering signed URLs forgeable. Additionally, the default setting for the artifact server address exposes the backend to the broader network, further compromising build outputs, including sensitive secrets and deployment credentials. As a result, attackers can read, overwrite, or delete artifacts from concurrently running jobs, facilitating potential unauthorized access and manipulation of critical workflows.
Affected Version(s)
act 0.2.81 <= 0.2.89
