Ghostwire

CVE-2026-67207: Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows...

HIGH CVSS 0.0

Published: July 30, 2026 | Last Modified: July 30, 2026

Description

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the access control expression to create, download, and restore backups without administrative privileges.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References