Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-85688: TEN Framework 0.11.71 allows remote file read and write
CVE-2026-85688 · published today
Summary
The TEN Framework version 0.11.71 lets anyone on the network send specially crafted requests to its designer feature and read or change any file on the server. This could let an attacker place malicious code, modify scheduled tasks, or add unauthorized login keys, potentially taking control of the system. Update to a patched version of TEN Framework and limit network access to the designer API to trusted users only.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ten-framework | ten-framework | <= 0.11.71 |
Original advisory text
TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer
TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.
References
- https://github.com/TEN-framework/ten-framework/issues/2187 issue-tracking
- https://github.com/TEN-framework/ten-framework product
- https://github.com/TEN-framework/ten-framework/blob/0.11.71/core/src/ten_manager... technical-description
- https://www.vulncheck.com/advisories/ten-framework-0.11.71-unauthenticated-file-... third-party-advisory
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Monitor software like this
Free during beta