CVE-2026-34042 - Vulnerability Analysis
HighCVSS: 8.2Last Updated: March 31, 2026
act - Remote Code Execution
Published: March 31, 2026Updated: March 31, 2026Remote Exploitable
Overview
act prior to 0.2.86 contains a remote code execution vulnerability caused by the built-in actions/cache server listening on all interfaces, letting remote attackers create and retrieve caches with arbitrary keys, exploit requires network access to the cache server.
Severity & Score
Severity: High
CVSS Score: 8.2
Impact
Remote attackers can execute arbitrary code within the Docker container by creating malicious caches.
Mitigation
Update to version 0.2.86 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-34042
- Severity
- High
- CVSS Score
- 8.2
- Type
- remote_code_execution
- Status
- new
CWE
- CWE-862
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N