← Retour à la recherche de CVE

CVE-2026-73519

WolfStack

Description

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node-s management port to enumerate all Docker and LXC containers on the host and execute arbitrary commands as root inside any container via the POST /api/containers/{runtime}/{id}/exec endpoint.

CVSS 9.8EPSS 0.786%Risque 1.05
Voir la source
Publication
2026-08-12 22:17:17
Versions concernées
<25.9.2
Type
Autre
Dernière modification
2026-08-13 14:17:13
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H