A new vulnerability, CVE-2026-2053, has been published with a CVSS score of 8.3, indicating a high severity risk. The issue affects the WSO2 API Manager, specifically its message flow component,…
CVE-2026-58053 (CVSS 9.9) — Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces
CVE. Sourced from nvd, summarised by Matproof.
AI Analysis
What changed and what to do.
A critical vulnerability, CVE-2026-58053, has been published with a CVSS score of 9.9, affecting Gitea act_runner when using the Docker backend up to version act 0.262.0. The flaw allows a malicious workflow to pass arbitrary container.options strings directly to the Docker job container's HostConfig, bypassing the configured privileged: false setting. This effectively enables an attacker to escalate privileges and gain host-level access, potentially compromising the entire CI/CD pipeline and underlying infrastructure.
Organizations using Gitea for source code management and CI/CD, particularly those in software development, fintech, healthcare, and public sector entities with DevOps pipelines, are directly affected. Any EU-regulated entity relying on Gitea act_runner for automated builds or testing should treat this as a high-priority security incident, as it undermines container isolation and could lead to data breaches or system takeover.
Compliance teams should immediately verify the version of act_runner in use and apply any available patches or updates from Gitea. If a fix is not yet released, implement compensating controls such as restricting workflow definitions to trusted users, disabling Docker backend usage, or enforcing strict network segmentation. Document the risk assessment and mitigation steps in your incident response records, as this vulnerability may require notification under GDPR or sector-specific regulations if exploitation is suspected.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More CVE updates
Latest in CVE.
A new vulnerability, CVE-2026-53914, has been published with a CVSS score of 6.7, affecting JetBrains Kotlin versions prior to 2.4.20. The issue allows code execution through unsafe deserialization…
A new vulnerability has been published under CVE-2026-57926, affecting JetBrains YouTrack versions prior to 2026.2.16593. The issue involves a prototype pollution attack in the websandbox bridge,…
A critical vulnerability has been published under CVE-2026-12415, affecting the Invoice Generator plugin for WordPress up to version 1.0. The flaw, rated 9.8 on the CVSS scale, allows privilege…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.