CVE-2026-76847 | nektos act up to 0.2.89 HTTP Artifacts V4 Backend artifacts_v4.go validateRunIDV4 workflow_run_backend_id privileges management

SecurityVulns

A vulnerability identified as critical has been detected in nektos act up to 0.2.89. Affected by this vulnerability is the function validateRunIDV4 of the file pkg/artifacts/artifacts_v4.go of the component HTTP Artifacts V4 Backend. This manipulation of the argument workflow_run_backend_id causes improper privilege management.

The identification of this vulnerability is CVE-2026-76847. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More