top of page
perceptive_background_267k.jpg

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access …

Published:

30 July 2026 at 00:00:00

Alert date:

30 July 2026 at 23:05:50

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

Wolf CMS through version 0.8.3.1 contains an authorization bypass vulnerability in the BackupRestoreController component. The flaw stems from a PHP operator precedence error in the permission check expression, causing incorrect evaluation of access control logic. Authenticated non-administrative users can exploit this to access restricted backup functionality. Attackers can create, download, and restore backups without requiring administrative privileges. The vulnerability is classified as an authorization bypass, allowing privilege escalation within the CMS. It affects all Wolf CMS installations up to and including version 0.8.3.1. The root cause is a logic flaw in PHP code rather than a missing check, making it a subtle but impactful security issue. No patch version is explicitly mentioned, suggesting users should review and update access control expressions manually or await an official fix.

Technical details

Mitigation steps:

Affected products:

Wolf CMS 0.8.3.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page