CVE-2026-67206
HIGHWolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-67206. PoCs published by anirbala98.
AI-analyzed exploit summary This PoC exploits an authenticated remote code execution (RCE) vulnerability in WolfCMS via its file manager plugin. The exploit logs in with provided credentials, creates a PHP file, and writes a web shell to achieve command execution.
Description
Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write malicious PHP content into the web-accessible FILES_DIR directory and trigger execution by requesting the file over HTTP.
Exploits (1)
This PoC exploits an authenticated remote code execution (RCE) vulnerability in WolfCMS via its file manager plugin. The exploit logs in with provided credentials, creates a PHP file, and writes a web shell to achieve command execution.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H