NVD CRITICAL: CVE-2026-73519 — WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret comp...
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate without any session, API key, or user account. Attackers can reach an affected node's management po
CVE-2026-73519