CVE-2026-44668: Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perform no local session check either, allowing an unauthenticated attacker to read, overwrite, deactivate, and permanently delete any boilerplate template in the system. This vulnerability is fixed in 1.8.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FACTION BoilerPlateConfig / AccessControlInterceptorto a version that resolves this vulnerability.Fixed in 1.8.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44668?
CVE-2026-44668 has a critical severity rating of 9.8.
How do I fix CVE-2026-44668?
To fix CVE-2026-44668, upgrade to FACTION version 1.8.3 or later.
What vulnerabilities are associated with CVE-2026-44668?
CVE-2026-44668 allows unauthenticated read, modify, and delete access to boilerplate templates.
What impact does CVE-2026-44668 have on software security?
CVE-2026-44668 can lead to unauthorized access and potentially expose sensitive data due to improper session validation.
Who is affected by CVE-2026-44668?
Users of FACTION framework versions prior to 1.8.3 are affected by CVE-2026-44668.