The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint a registration token and register a malicious Actions runner that executes workflow jobs with access to repository secrets and source code.
We have discovered 714 live websites that are affected by CVE-2026-24059.
| 181 websites | |
| 187 websites | |
| 97 websites | |
| 44 websites | |
| 36 websites | |
| 19 websites | |
| 14 websites | |
| 14 websites | |
| 14 websites | |
| 9 websites |
| .com | 175 websites |
| .net | 74 websites |
| .org | 70 websites |
| .de | 65 websites |
| .ru | 30 websites |
| .fr | 25 websites |
| .eu | 15 websites |
| .io | 12 websites |
| .nl | 11 websites |
| .it | 9 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.********.com | ***,*** | ||
| ***.*************.org | ***,*** | ||
| *****.**********.eu | ***,*** | ||
| ***.*******.net | ***,*** | ||
| ******************.com | *,***,*** | ||
| **********.es | *,***,*** | ||
| ****.********.ch | *,***,*** | ||
| ***.*********.rip | *,***,*** | ||
| ***.************.com | *,***,*** | ||
| *********.nl | *,***,*** |
FAQ