Authentication Bypass in WolfStack Product by Wolf Software Systems
CVE-2026-73519
9.3CRITICAL
What is CVE-2026-73519?
WolfStack versions prior to 25.9.2 are vulnerable due to a hard-coded cluster-authentication secret embedded in the source code. This flaw allows remote attackers to authenticate without credentials by using the X-WolfStack-Secret header. By exploiting this vulnerability, attackers can bypass necessary authentication checks and gain unauthorized access to the management interface. This enables them to enumerate Docker and LXC containers and execute arbitrary commands as root within those containers via the targeted API endpoint.
Affected Version(s)
WolfStack 0
