{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/wolf-cms/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wolf CMS (\u003c= 0.8.3.1)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Wolf CMS"],"content_html":"\u003cp\u003eWolf CMS versions 0.8.3.1 and earlier contain a critical remote code execution (RCE) vulnerability (CVE-2026-67206) residing within the \u003ccode\u003eFileManagerController\u003c/code\u003e. The vulnerability stems from improper validation of file extensions in the \u003ccode\u003ecreate_file()\u003c/code\u003e and \u003ccode\u003esave()\u003c/code\u003e functions. An attacker who has authenticated to the CMS and possesses the \u003ccode\u003efile_manager_mkfile\u003c/code\u003e capability can exploit this flaw to create and upload arbitrary PHP files into the web-accessible \u003ccode\u003eFILES_DIR\u003c/code\u003e directory. Once the file is uploaded, an attacker can trigger remote code execution by sending an HTTP request directly to the newly created file. This vulnerability poses a significant risk to organizations using Wolf CMS, as it effectively elevates the access of a standard CMS user to full system code execution.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Wolf CMS administrative interface using valid, potentially compromised, credentials.\u003c/li\u003e\n\u003cli\u003eAttacker verifies they possess the \u003ccode\u003efile_manager_mkfile\u003c/code\u003e capability within the application.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the File Manager module within the administrative dashboard.\u003c/li\u003e\n\u003cli\u003eAttacker invokes the \u003ccode\u003ecreate_file()\u003c/code\u003e or \u003ccode\u003esave()\u003c/code\u003e function to create a new file, providing a malicious payload formatted as PHP code.\u003c/li\u003e\n\u003cli\u003eAttacker bypasses the missing server-side extension validation, ensuring the file is saved with a \u003ccode\u003e.php\u003c/code\u003e extension in the \u003ccode\u003eFILES_DIR\u003c/code\u003e directory.\u003c/li\u003e\n\u003cli\u003eApplication writes the attacker-supplied PHP content to the server disk at the specified path.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the execution of the malicious script by navigating to the file path via a standard browser HTTP request.\u003c/li\u003e\n\u003cli\u003eWeb server executes the PHP payload, resulting in remote code execution under the context of the web server user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated attacker to achieve remote code execution on the underlying web server. This can lead to full compromise of the web application, potential lateral movement within the hosting environment, and exfiltration of sensitive configuration or database information. Given the nature of the application, this flaw is particularly dangerous for small-to-medium organizations relying on Wolf CMS for content management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately audit user roles and capabilities in Wolf CMS to identify accounts with the \u003ccode\u003efile_manager_mkfile\u003c/code\u003e privilege; restrict this access to trusted administrators only.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests to files created within the \u003ccode\u003eFILES_DIR\u003c/code\u003e path, particularly those ending in \u003ccode\u003e.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect POST requests to the \u003ccode\u003eFileManagerController\u003c/code\u003e that coincide with file creation events.\u003c/li\u003e\n\u003cli\u003eReview the Wolf CMS GitHub repository for updates and patch to a version beyond 0.8.3.1 immediately once available.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T21:32:01Z","date_published":"2026-07-30T21:31:53Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wolf-cms-rce/","summary":"Wolf CMS versions up to 0.8.3.1 contain a remote code execution vulnerability in the FileManagerController allowing authenticated users with specific permissions to upload and execute arbitrary PHP files.","title":"Authenticated Remote Code Execution in Wolf CMS","url":"https://feed.craftedsignal.io/briefs/2026-07-wolf-cms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Wolf CMS","version":"https://jsonfeed.org/version/1.1"}