← Πίσω στην αναζήτηση CVE

CVE-2026-73519

WolfStack

Περιγραφή

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node-s management port to enumerate all Docker and LXC containers on the host and execute arbitrary commands as root inside any container via the POST /api/containers/{runtime}/{id}/exec endpoint.

CVSS 9.8EPSS 0.786%Κίνδυνος 1.05
Προβολή πηγής
Δημοσίευση
2026-08-12 22:17:17
Επηρεαζόμενες εκδόσεις
<25.9.2
Τύπος
Άλλο
Τελευταία τροποποίηση
2026-08-13 14:17:13
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H