CVE-2026-73802 is an improper privilege management vulnerability in Gitea act_runner that allows workflow-controlled container options to bypass the intended restrictions of disabled privileged mode. RunContext.options() combines workflow options with runner-level options, and mergeContainerConfigs() parses them into Docker HostConfig settings. When privileged mode is disabled, only the Privileged setting is forced to false; host namespace settings, expanded capabilities, and security-profile overrides remain effective. Although sanitizeConfig() filters binds and mounts, it does not remove these dangerous settings. A workflow author can exploit the resulting configuration to escape a Docker-backed job container and execute arbitrary commands as root on the runner host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical vulnerability affecting gitea.com/gitea/runner, classified under CWE-269 (Improper Privilege Management). Its CVSS v3 score is 9.9, indicating network-accessible exploitation requiring low privileges and no user interaction, with high confidentiality, integrity, and availability impacts. The reference provides no detailed exploitation mechanism. Update the library and related packages to version 1.0.9-0.20260731160927-34bfa1915022 or later.
A container sandbox escape in Gitea act_runner, rated CVSS 3.1 9.9. An attacker able to submit workflows to a Docker-backed runner can supply unsafe container options that bypass isolation despite privileged mode being disabled. This enables root command execution on the runner host, theft of secrets and deployment credentials, and access to adjacent jobs and internal build infrastructure. Shared runners accepting untrusted workflows are particularly exposed.
A container-isolation bypass in Gitea act_runner allows workflow authors to preserve host namespace access, expanded capabilities, and disabled security profiles even when runner privileged mode is disabled. An attacker able to submit workflows can escape the job container and execute commands as root on the runner host, exposing secrets, adjacent jobs, and reachable internal infrastructure. The advisory rates the impact critical for shared runners accepting untrusted workflows and high for single-tenant runners relying on disabled privileged mode. The affected package range starts at version 0 and ends before fixed version 1.0.9-0.20260731160927-34bfa1915022.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.