CVE-2026-44668Patch

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check either, allowing an unauthenticated attacker to read, overwrite, deactivate, and permanently delete any boilerplate template in the system. This vulnerability is fixed in 1.8.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-27: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-27: 105-27
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • PurpleOps@PurpleOps_io
    Patch

    5 Critical CVEs to Fix Now - Totolink A8000RU, Lumiverse, DIAView Affected: Totolink A8000RU Web Management Interface; Lumiverse; FACTION; DIAView Today’s critical CVEs span networking gear and AI platform components, with several exploitable remotely. - CVE-2026-44450 (CVSS 9.9) Lumiverse MCP server creation endpoint forwards unvalidated args to a child process, enabling OS command execution by authenticated users on affected versions prior to 0.9.7. - CVE-2026-9405 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface setGameSpeedCfg allows OS command injection when enable is manipulated; remote. - CVE-2026-9406 (CVSS 9.8) Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface setRemoteCfg manipulation of enable leads to OS command injection; remote. - CVE-2026-9642 (CVSS 9.8) DIAView project suffers an authentication bypass enabling unauthenticated remote access to configured databases due to an incomplete mitigation of CVE-2025-62582. - CVE-2026-44668 (CVSS 9.8) FACTION's AccessControlInterceptor permits unauthenticated access to boilerplate templates due to missing session checks; attackers can read, overwrite, deactivate, or purge templates; fixed in 1.8.3. Action - Patch/upgrade to fixed versions called out (Lumiverse 0.9.7; FACTION 1.8.3; apply vendor advisory latest for DIAView and Totolink). - Prioritize internet-facing Totolink A8000RU devices and other publicly exposed endpoints. - If no fix yet, apply vendor-recommended mitigations (restrict access to DIAView components; disable exposed features where feasible). - Add detections for exploitation patterns implied by the CVEs (process spawning from cstecgi.cgi; unusual enable parameter values; remote command patterns). - Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) focusing on /cgi-bin/cstecgi.cgi activities. - Validate remediation (version checks, config verification) and monitor for reversion or new attempts.

    Post summary

    This advisory announces five critical CVEs across networking and AI platform devices, details their technical impact, and provides explicit patch versions and mitigation guidance to remediate the vulnerabilities.

    00010287
    575 followersView on X

Explore more