Product
The 'act' tool's HTTP Artifacts V4 backend suffers from an authentication bypass and hardcoded HMAC key vulnerability (CVE-2026-76847), allowing unauthorized network actors to access, modify, or delete artifacts and exfiltrate secrets.