CVE-2026-44668

CRITICAL

Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates

Title source: cna
STIX 2.1

Description

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check either, allowing an unauthenticated attacker to read, overwrite, deactivate, and permanently delete any boilerplate template in the system. This vulnerability is fixed in 1.8.3.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0036
EPSS Percentile 28.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
factionsecurity/faction < 1.8.3
Published May 26, 2026
Tracked Since May 26, 2026