


Perceptive Security
SOC/SIEM Consultancy

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP fil…
Published:
30 July 2026 at 00:00:00
Alert date:
30 July 2026 at 23:05:50
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
Wolf CMS through version 0.8.3.1 contains a remote code execution vulnerability in the FileManagerController component. The flaw stems from missing file extension validation in the create_file() and save() functions, allowing authenticated attackers to create arbitrary PHP files. Attackers possessing the file_manager_mkfile capability can write malicious PHP content directly into the web-accessible FILES_DIR directory. Once written, the malicious file can be executed by simply requesting it over HTTP, resulting in full remote code execution. The vulnerability requires authentication but no elevated administrative privileges beyond the file manager capability. This affects all versions of Wolf CMS up to and including 0.8.3.1. A proof-of-concept advisory has been published on GitHub, and VulnCheck has also documented the issue.
Technical details
Mitigation steps:
Affected products:
Wolf CMS 0.8.3.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67206
https://github.com/Caycon/cve-advisories/blob/main/2026/WolfCms/CVE-2026-67206.md
https://www.vulncheck.com/advisories/wolf-cms-authenticated-rce-via-filemanagercontroller-file-upload
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
