Sceawere

Vulnerability Detail

CVE-2026-41560UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WXD Backup Lite Access Control

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
16h ago
Vendor
wxdlabs
Product
WXD Backup Lite
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-06T09:17:53.730Z",
  "pubdate": "2026-10-06T09:17:53.730Z",
  "executiveSummary": "WXD Backup Lite versions 1.0.2 and earlier are susceptible to an unauthenticated broken access control vulnerability. This flaw resides within the application's authorization mechanism, allowing unauthorized entities to bypass security checks that should restrict sensitive functionality.\nThe vulnerability allows an unauthenticated attacker to interact with backend administrative or sensitive backup functions without providing valid session credentials. This bypass effectively negates the authentication layer of the product.\nThe impact includes potential unauthorized access to system backups, potential data exfiltration, and the ability to manipulate backup configurations. Given the nature of backup software, this vulnerability represents a significant risk to data confidentiality and integrity.\nExploitation requires network access to the target instance but does not necessitate prior authentication, making this a high-severity entry point for attackers to compromise managed data.",
  "technicalDetails": "The root cause of this vulnerability is an improperly implemented authorization check within the WXD Backup Lite application logic. Specifically, the software fails to validate the authentication state or authorization tokens for sensitive requests directed at core backup management endpoints.\nThe vulnerable component handles administrative requests by checking for the presence of certain parameters or specific HTTP headers, rather than verifying the integrity and legitimacy of an active session token issued by the authentication service. Because the application logic defaults to a 'permit' state when these checks are omitted or malformed, an attacker can directly invoke sensitive function handlers.\nThe attack flow begins with the attacker identifying the target URL endpoints associated with backup management or system configuration. By crafting direct HTTP requests to these endpoints, the attacker circumvents the standard login flow. Since the backend services do not re-validate the user's session state upon receiving these requests, the server process proceeds to execute the requested administrative operations with elevated privileges.\nThis vulnerability effectively exposes the entire administrative interface to the network. An attacker can leverage this to trigger unauthorized backup processes, list existing backup files, or potentially modify configuration files that govern the application's storage path. If the backup management functions include file download or upload capabilities, the attacker can move laterally to extract sensitive database contents or configuration backups stored by the application.\nThe vulnerability is confirmed in versions 1.0.2 and below. Because the flaw exists within the application's internal request processing architecture, it is independent of the underlying web server configuration. The exposure is global for any deployment where the management interface is reachable over a network, including those exposed to the public internet. No specific privilege requirements are needed to initiate the exploitation, as the system erroneously treats unauthenticated requests as authorized by default."
}
CVE-2026-41560: WXD Backup Lite Access Control (HIGH Severity, CVSS: 7.5) | Sceawere