Summary
CVE-2026-73519 affects WolfStack, a Rust-based server infrastructure management platform, and stems from a hard-coded cluster authentication secret compiled into every build (CWE-798). The flaw allows a remote, unauthenticated attacker to bypass authentication on the management interface and execute arbitrary commands as root inside managed containers. The vulnerability carries a critical severity rating (CVSS v4.0 base score 9.3).
Technical details
- Root cause: WolfStack ships with a static authentication secret embedded in the compiled binary, used to gate access to the management API.
- Trigger condition: An attacker sends the hard-coded secret in the
X-WolfStack-Secretrequest header to reach therequire_auth()authentication gate without possessing any valid session, API key, or user account. Nodes are exposed if they lack a custom/etc/wolfstack/custom-cluster-secret, were upgraded from older builds retaining default peer configuration, or run withWOLFSTACK_ACCEPT_DEFAULT_SECRET=1. - Attack vector: Network — requires only reachability to the WolfStack management port; no authentication or user interaction needed.
- Impact: Once authenticated as a trusted peer, an attacker can enumerate all Docker and LXC containers on the host and execute arbitrary commands as root inside any container via
POST /api/containers/{runtime}/{id}/exec, resulting in full compromise of confidentiality, integrity, and availability of the host and its workloads.
Affected software
- WolfStack versions prior to 25.9.2 (all versions through 25.9.1)
- Nodes that had already rotated to a per-install secret are not affected
Severity
- CVSS v4.0 Base Score: 9.3 (CRITICAL) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - CVSS v3.1 Base Score: 9.8 (CRITICAL) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade WolfStack to version 25.9.2 or later.
- If patching is not immediately possible:
- Rotate the cluster secret via Settings → Security → Rotate cluster secret so a per-install secret replaces the default value.
- Set the environment variable
WOLFSTACK_REJECT_DEFAULT_SECRET=1and restart the service to reject the hard-coded default. - Restrict network access to the WolfStack management port behind a VPN or IP allowlist to prevent unauthenticated remote reachability.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Meta tag (
description):WolfStack Server Management Platform - Login - Page title:
WolfStack – Login

