
🚨Critical - Dalfox Server Mode Unauthenticated RCE via found-action (CVE-2026-45087) When Dalfox runs in REST API server mode (dalfox server), it binds to 0.0.0.0:6664 with no authentication by default. An unauthenticated attacker can send a POST /scan request that supplies arbitrary found-action and found-action-shell values. These are executed via exec. Command whenever a scan finding is triggered, resulting in full remote code execution on the host. 👉Affected: dalfox <= 2.12.0
Post summary
The post announces CVE-2026-45087, detailing an unauthenticated RCE in Dalfox server mode via POST /scan with found-action values, but offers no PoC, patch, or evidence of active exploitation.

