Unrated severityNVD Advisory· Published Jul 30, 2026· Updated Aug 3, 2026
Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
CVE-2026-67206
Description
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger execution by requesting the file over HTTP.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Caycon/cve-advisories/blob/main/2026/WolfCms/CVE-2026-67206.mdmitretechnical-descriptionexploit
- www.vulncheck.com/advisories/wolf-cms-authenticated-rce-via-filemanagercontroller-file-uploadmitrethird-party-advisory
News mentions
0No linked articles in our index yet.