PT-2026-66600 · Wolfcms · Wolf Cms

·

CVE-2026-67206

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wolf CMS versions prior to 0.8.3.2
Description An issue in the FileManagerController allows authenticated attackers with the file manager mkfile capability to achieve remote code execution. This is possible due to missing file extension validation in the create file() and save() functions, enabling the creation of arbitrary PHP files within the web-accessible FILES DIR directory. Execution is triggered by requesting the created file over HTTP.
Recommendations Update Wolf CMS to version 0.8.3.2 or later. As a temporary mitigation, restrict the file manager mkfile capability to trusted users only.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67206

Affected Products

Wolf Cms