Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-73519: WolfStack < 25.9.2: Unauthorized Access to Docker and LXC Containers
CVE-2026-73519 · published 22 days ago
Summary
WolfStack versions before 25.9.2 have a security flaw that allows unauthorized access to Docker and LXC containers. This means that an attacker could potentially gain access to sensitive information and execute commands on your system. To fix this, update WolfStack to version 25.9.2 or later.
What to do
- Update wolfsoftwaresystemsltd wolfstack to version 25.9.2 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wolfsoftwaresystemsltd | wolfstack | < 25.9.2 |
Original advisory text
WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node's management port to enumerate all Docker and LXC containers on the host and execute arbitrary commands as root inside any container via the POST /api/containers/{runtime}/{id}/exec endpoint.
References
- https://github.com/wolfsoftwaresystemsltd/WolfStack/security/advisories/GHSA-r3m... vendor-advisory
- https://github.com/wolfsoftwaresystemsltd/WolfStack/releases?page=7#release-v25.... release-notes
- https://www.vulncheck.com/advisories/wolfstack-hard-coded-secret-authentication-... third-party-advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published12 Aug 2026
Updated3 Sep 2026
First seen12 Aug 2026
Monitor software like this
Free during beta