CVE-2026-73519 is a critical authentication bypass vulnerability in WolfStack versions before 25.9.2. The flaw is caused by a hard-coded cluster-authentication secret compiled into affected builds and exposed as a constant in the authentication module. The secret is accepted by the require_auth() gate through a dedicated request header, allowing an unauthenticated remote attacker to satisfy authentication checks without a valid session, API key, or user account. If the attacker can reach an affected node's management interface, the bypass grants access to management API functionality, including container enumeration and command execution operations against Docker and LXC workloads. The exposed execution capability allows arbitrary commands to be run as root inside targeted containers.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused proof-of-concept for CVE-2026-73519 affecting WolfStack. It contains two files: a README documenting the vulnerability, impact, and usage, and a single Bash exploit script (poc.sh). The exploit is not part of a larger framework. The core capability is unauthenticated remote command execution against WolfStack-managed containers by abusing a hardcoded cluster authentication secret. The script first demonstrates that a POST request to the container exec API without authentication returns HTTP 401, then repeats the same request with the X-WolfStack-Secret header set to the shared default secret. If the target still accepts that secret, WolfStack treats the request as authenticated and executes the supplied command inside the specified Docker container. The exploit targets WolfStack's REST API, specifically the POST /api/containers/docker/{container}/exec route. The README also notes that the same authentication bypass can expose other require_auth-protected routes, including container enumeration endpoints such as /api/containers/docker and /api/containers/lxc, as well as broader management functionality. The demonstrated payload sends a JSON body containing a command string (id; hostname), which confirms code execution and root privileges inside the container. Repository structure is minimal and operational: README.md provides vulnerability context, affected/fixed versions, and manual curl examples; poc.sh is the executable entry point implementing the attack with curl. Because the payload is hardcoded and basic but functional, the exploit is best classified as OPERATIONAL rather than a mere detection script or a weaponized framework module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.