SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-85688

CRITICAL · CVSS 9.8 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The TEN Framework version 0.11.71 is vulnerable to unauthenticated arbitrary file read and write vulnerabilities in its TMAN Designer API endpoints, allowing attackers to exploit these weaknesses via POST and PUT requests. This could lead to unauthorized access to sensitive files or the injection of malicious content, potentially enabling code execution on the affected systems. Organizations using this framework should prioritize patching or mitigating this vulnerability to protect against severe security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85688
Severity
CRITICAL
CVSS
9.8
EPSS
0.40%

Original NVD Description

TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.