Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-85688

CRITICAL NVD
CVSS Score 9.8
Severity CRITICAL
Published Sep 04, 2026
Vendor unknown

Description

TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.

References