FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check either, allowing an unauthenticated attacker to read, overwrite, deactivate, and permanently delete any boilerplate template in the system. This vulnerability is fixed in 1.8.3.
Metrics
Affected Vendors & Products
References
History
Wed, 27 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Factionsecurity
Factionsecurity faction |
|
| Vendors & Products |
Factionsecurity
Factionsecurity faction |
Tue, 26 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check either, allowing an unauthenticated attacker to read, overwrite, deactivate, and permanently delete any boilerplate template in the system. This vulnerability is fixed in 1.8.3. | |
| Title | Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-05-26T17:43:49.177Z
Updated: 2026-05-27T14:01:36.895Z
Reserved: 2026-05-07T16:20:08.659Z
Link: CVE-2026-44668
Updated: 2026-05-27T14:00:32.750Z
Status : Deferred
Published: 2026-05-26T18:16:50.270
Modified: 2026-05-27T15:16:28.060
Link: CVE-2026-44668
No data.