No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Factionsecurity
Factionsecurity faction |
|
| Vendors & Products |
Factionsecurity
Factionsecurity faction |
Tue, 26 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check either, allowing an unauthenticated attacker to read, overwrite, deactivate, and permanently delete any boilerplate template in the system. This vulnerability is fixed in 1.8.3. | |
| Title | Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T14:01:36.895Z
Reserved: 2026-05-07T16:20:08.659Z
Link: CVE-2026-44668
Updated: 2026-05-27T14:00:32.750Z
Status : Deferred
Published: 2026-05-26T18:16:50.270
Modified: 2026-05-27T15:16:28.060
Link: CVE-2026-44668
No data.
OpenCVE Enrichment
Updated: 2026-05-26T20:30:15Z