PatchSiren cyber security CVE debrief
CVE-2026-67207 wolfcms CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T20:18:14.180Z and has not been modified since then. The NVD entry is currently Deferred. Wolf CMS 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController due to a PHP operator precedence flaw. This allows authenticated non-administrative users to create, download, and restore backups without administrative privileges. The vulnerability impacts web applications using Wolf CMS 0.8.3.1, particularly those with exposed BackupRestoreController functionality. Users of Wolf CMS 0.8.3.1, administrators of web applications, security teams monitoring for potential exploitation of authorization bypass vulnerabilities, and operators responsible for vulnerability management and patching should be aware of this vulnerability. They should verify the presence of Wolf CMS 0.8.3.1 in their environments and review access controls for BackupRestoreController. Defenders should verify the existence of Wolf CMS 0.8.3.1 deployments, review BackupRestoreController access controls, and monitor for suspicious backup activity. Evidence is limited to CVE and NVD details.
- Vendor
- wolfcms
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-30
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-30
- Advisory updated
- 2026-07-31
Who should care
Users of Wolf CMS 0.8.3.1, administrators of web applications, security teams monitoring for potential exploitation of authorization bypass vulnerabilities, and operators responsible for vulnerability management and patching should be aware of this vulnerability. They should verify the presence of Wolf CMS 0.8.3.1 in their environments and review access controls for BackupRestoreController.
Technical summary
The authorization bypass vulnerability in Wolf CMS 0.8.3.1 is caused by a PHP operator precedence flaw in the permission check expression of BackupRestoreController. This allows authenticated non-administrative users to create, download, and restore backups without administrative privileges. The vulnerability impacts web applications using Wolf CMS 0.8.3.1, particularly those with exposed BackupRestoreController functionality.
Defensive priority
Authenticated non-administrative users can exploit an authorization bypass vulnerability in Wolf CMS 0.8.3.1 to access restricted backup functionality. Verify and restrict BackupRestoreController access.
Recommended defensive actions
- Verify and restrict access to BackupRestoreController
- Inventory Wolf CMS installations for potential exposure
- Monitor for suspicious backup activity
- Apply vendor patches when available
- Implement compensating controls for backup functionality
Evidence notes
The CVE-2026-67207 record indicates an authorization bypass vulnerability in Wolf CMS 0.8.3.1 due to a PHP operator precedence flaw. Limited information is available on affected scope and vendor remediation. Defenders should verify the existence of Wolf CMS 0.8.3.1 deployments, review BackupRestoreController access controls, and monitor for suspicious backup activity. Evidence is limited to CVE and NVD details.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-30T20:18:14.180Z and has not been modified since then.