CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-67308

criticalCVSS 10covered by 1 sourcefirst seen 2026-08-01
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling command execution and exfiltration of secrets including GITHUB_TOKEN and AWS credentials on self-hosted runners.

⚡ Watch CVE-2026-67308

Get an email if CVE-2026-67308 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-67308

CVE.org record

Embed the live status

CVE-2026-67308 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-67308 status](https://www.csirts.com/badge/CVE-2026-67308)](https://www.csirts.com/cve/CVE-2026-67308)