Wolfcms · Wolf Cms · CVE-2026-67207
**Name of the Vulnerable Software and Affected Versions**
Wolf CMS versions prior to 0.8.3.2
**Description**
An authorization bypass exists in the `BackupRestoreController` due to a PHP operator precedence flaw in the permission check expression. This allows authenticated users without administrative privileges to bypass access controls and perform restricted actions, including creating, downloading, and restoring backups.
**Recommendations**
Update Wolf CMS to version 0.8.3.2 or later.