{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/wolfstack/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-73519"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WolfStack (\u003c 25.9.2)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WolfStack"],"content_html":"\u003cp\u003eWolfStack versions prior to 25.9.2 contain a critical security flaw identified as CVE-2026-73519. The vulnerability stems from a hard-coded cluster-authentication secret, defined as a constant within the source code file 'src/auth/mod.rs' and included in every build. This implementation flaw allows any remote, unauthenticated attacker to bypass the 'require_auth()' authentication gate. By providing the known secret value in the 'X-WolfStack-Secret' HTTP header, an attacker can gain unauthorized access to the node's management port. Once authenticated, an attacker can enumerate running Docker and LXC containers on the target host and execute arbitrary commands with root privileges inside these containers via the '/api/containers/{runtime}/{id}/exec' endpoint. Given the critical severity (CVSS 9.8) and the ease of exploitation, immediate patching is required for all production deployments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify exposed WolfStack management ports (typically associated with the product's cluster management functionality).\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the management API with the required header 'X-WolfStack-Secret' containing the hard-coded secret value.\u003c/li\u003e\n\u003cli\u003eThe 'require_auth()' gate accepts the request, granting the attacker unauthenticated access to the management API.\u003c/li\u003e\n\u003cli\u003eAttacker queries the enumeration endpoint to list all active Docker and LXC container IDs on the target host.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a high-value container (e.g., database or service container) for lateral movement or data extraction.\u003c/li\u003e\n\u003cli\u003eAttacker issues a POST request to '/api/containers/{runtime}/{id}/exec' to inject and execute arbitrary commands.\u003c/li\u003e\n\u003cli\u003eThe WolfStack node executes the malicious command payload as root inside the target container.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved via arbitrary command execution and potential container escape or persistence within the containerized environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full control over containerized workloads, including data exfiltration, service disruption, and lateral movement within the cluster. Because the 'exec' endpoint facilitates root-level access, attackers can modify container configurations, install persistent backdoors, or potentially exploit container engine vulnerabilities to break out to the host system. This affects any enterprise environment utilizing WolfStack for container orchestration and management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all WolfStack instances to version 25.9.2 or later immediately to remove the hard-coded secret.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the WolfStack management port to trusted management subnets via firewall rules.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious requests containing the 'X-WolfStack-Secret' header if immediate patching is not possible.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized access patterns against the '/api/containers/' management endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T22:52:00Z","date_published":"2026-08-12T22:52:00Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wolfstack-hardcoded-secret/","summary":"WolfStack versions prior to 25.9.2 contain a hard-coded authentication secret that allows unauthenticated remote attackers to bypass authentication and achieve root-level command execution within containerized workloads.","title":"Hard-coded Authentication Secret in WolfStack","url":"https://feed.craftedsignal.io/briefs/2026-08-wolfstack-hardcoded-secret/"}],"language":"en","title":"CraftedSignal Threat Feed - WolfStack","version":"https://jsonfeed.org/version/1.1"}