Unauthenticated File Read and Write Vulnerability in TEN Framework by TEN
CVE-2026-85688
9.3CRITICAL
What is CVE-2026-85688?
The TEN Framework 0.11.71 is susceptible to unauthenticated arbitrary file read and write operations due to vulnerabilities in the TMAN Designer's file-content API endpoints. Attackers can exploit this weakness by sending POST and PUT requests to the /api/designer/v1/file-content endpoints, potentially allowing them to access sensitive files or inject malicious content into critical system paths. This could enable unauthorized code execution through compromised files such as authorized_keys, cron jobs, or executable graph files, posing a serious security risk.
Affected Version(s)
ten-framework 0 <= 0.11.71
