Authentication Bypass in WolfStack Product by Wolf Software Systems
CVE-2026-73519

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73519?

WolfStack versions prior to 25.9.2 are vulnerable due to a hard-coded cluster-authentication secret embedded in the source code. This flaw allows remote attackers to authenticate without credentials by using the X-WolfStack-Secret header. By exploiting this vulnerability, attackers can bypass necessary authentication checks and gain unauthorized access to the management interface. This enables them to enumerate Docker and LXC containers and execute arbitrary commands as root within those containers via the targeted API endpoint.

Affected Version(s)

WolfStack 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dostxodjayev Abdullox (@squeeze440)
.