{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/ten/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ten:framework:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85688"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TEN Framework (0.11.71)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","webserver"],"_cs_type":"advisory","_cs_vendors":["TEN"],"content_html":"\u003cp\u003eTEN Framework version 0.11.71 is impacted by a critical vulnerability (CVE-2026-85688) affecting the TMAN Designer component. The vulnerability resides in the /api/designer/v1/file-content API endpoints, which fail to properly validate requests. This flaw allows unauthenticated attackers to perform arbitrary file reads and writes on the underlying host system. By sending maliciously crafted POST or PUT requests to these endpoints, an attacker can read sensitive configuration files or overwrite system files. Successful exploitation enables remote code execution through methods such as modifying SSH authorized_keys, appending malicious cron jobs, or injecting code into executable graph files used by the framework. Given the CVSS score of 9.8, this vulnerability poses a severe risk to any internet-exposed TEN Framework instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing TEN Framework TMAN Designer instances.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request targeting the /api/designer/v1/file-content endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker uses the vulnerability to read local system configuration files to map internal paths.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious payload, such as a reverse shell script or an SSH public key.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP PUT request to the same endpoint to overwrite a sensitive system file (e.g., /home/user/.ssh/authorized_keys).\u003c/li\u003e\n\u003cli\u003eIf targeting cron, the attacker writes a malicious job definition to /etc/cron.d/ or /var/spool/cron/.\u003c/li\u003e\n\u003cli\u003eThe system executes the injected code or grants unauthorized access, completing the compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full system compromise of the server running TEN Framework. Attackers gain the ability to exfiltrate sensitive data, establish persistent backdoors via SSH keys or cron jobs, and execute arbitrary code with the privileges of the service user. This vulnerability affects all deployments of TEN Framework 0.11.71 and carries a high risk of automated exploitation by threat actors scanning for vulnerable web applications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all instances of TEN Framework to a patched version once released by the vendor.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the TMAN Designer API endpoints to trusted administrative IP addresses using a firewall or ingress controller.\u003c/li\u003e\n\u003cli\u003eAudit server logs for unauthorized HTTP POST or PUT requests to /api/designer/v1/file-content.\u003c/li\u003e\n\u003cli\u003eImplement integrity monitoring on critical system files like /home/\u003cem\u003e/.ssh/authorized_keys and /etc/cron.\u003c/em\u003e to detect unauthorized modifications.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T15:26:41Z","date_published":"2026-09-04T15:26:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ten-framework-rce/","summary":"TEN Framework version 0.11.71 contains unauthenticated file read and write vulnerabilities in its API endpoints, enabling remote code execution via file system manipulation.","title":"Unauthenticated Arbitrary File Read and Write in TEN Framework","url":"https://feed.craftedsignal.io/briefs/2026-09-ten-framework-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - TEN","version":"https://jsonfeed.org/version/1.1"}