← Zurück zur CVE-Suche

CVE-2026-73519

WolfStack

Beschreibung

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node-s management port to enumerate all Docker and LXC containers on the host and execute arbitrary commands as root inside any container via the POST /api/containers/{runtime}/{id}/exec endpoint.

CVSS 9.8EPSS 0.786%Risiko 1.05
Quelle öffnen
Veröffentlicht
2026-08-12 22:17:17
Betroffene Versionen
<25.9.2
Typ
Sonstiges
Zuletzt geändert
2026-08-13 14:17:13
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H