Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 04 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files. | |
| Title | TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T14:32:33.110Z
Reserved: 2026-09-04T13:51:43.604Z
Link: CVE-2026-85688
No data.
Status : Received
Published: 2026-09-04T15:17:46.657
Modified: 2026-09-04T15:17:46.657
Link: CVE-2026-85688
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:45:04Z
