


Perceptive Security
SOC/SIEM Consultancy

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access …
Published:
30 July 2026 at 00:00:00
Alert date:
30 July 2026 at 23:05:50
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Wolf CMS through version 0.8.3.1 contains an authorization bypass vulnerability in the BackupRestoreController component. The flaw stems from a PHP operator precedence error in the permission check expression, causing incorrect evaluation of access control logic. Authenticated non-administrative users can exploit this to access restricted backup functionality. Attackers can create, download, and restore backups without requiring administrative privileges. The vulnerability is classified as an authorization bypass, allowing privilege escalation within the CMS. It affects all Wolf CMS installations up to and including version 0.8.3.1. The root cause is a logic flaw in PHP code rather than a missing check, making it a subtle but impactful security issue. No patch version is explicitly mentioned, suggesting users should review and update access control expressions manually or await an official fix.
Technical details
Mitigation steps:
Affected products:
Wolf CMS 0.8.3.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67207
https://github.com/Caycon/cve-advisories/blob/main/2026/WolfCms/CVE-2026-67207.md
https://www.vulncheck.com/advisories/wolf-cms-authorization-bypass-via-backuprestorecontroller
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
