{"apiVersion":"1.0","identifier":"CVE-2026-73519","description":"WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node-s management port to enumerate all Docker and LXC containers on the host and execute arbitrary commands as root inside any container via the POST /api/containers/{runtime}/{id}/exec endpoint.","publishedAt":"2026-08-12T22:17:17","lastModifiedAt":"2026-08-13T14:17:13","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73519","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00786,"riskScore":1.05,"affectedProduct":"WolfStack","affectedVersions":"<25.9.2","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-73519","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-73519","en":"https://www.redsauce.net/en/cves/CVE-2026-73519","fr":"https://www.redsauce.net/fr/cves/CVE-2026-73519","pt":"https://www.redsauce.net/pt/cves/CVE-2026-73519","de":"https://www.redsauce.net/de/cves/CVE-2026-73519","sk":"https://www.redsauce.net/sk/cves/CVE-2026-73519","el":"https://www.redsauce.net/el/cves/CVE-2026-73519"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-73519"}}