Sceawere

Vulnerability Detail

CVE-2026-97240UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

StifLi Backup Unauthenticated Data Exposure

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Esteban
Product
StifLi Backup Tools
Attack Type
CWE-201 Insertion of Sensitive Information Into Sent Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-30T13:17:35.747Z",
  "pubdate": "2026-09-30T13:17:35.747Z",
  "executiveSummary": "StifLi Backup Tools versions 2.2.7 and earlier contain a critical vulnerability characterized as Unauthenticated Sensitive Data Exposure. The flaw allows remote, unauthenticated attackers to access and exfiltrate sensitive configuration files, backup metadata, or internal system data without requiring valid credentials.\nThis vulnerability poses a significant risk to organizational confidentiality and integrity. By bypassing authentication mechanisms, unauthorized parties can gain visibility into proprietary backup structures and potentially sensitive operational data. The attack surface is exposed directly via the network, necessitating no prior access to the underlying server environment. Given the nature of backup tools, successful exploitation may lead to full system compromise, exposure of credentials stored within backups, or the unauthorized acquisition of sensitive intellectual property.\nThe risk is exacerbated by the lack of defensive controls at the application entry point, which fails to enforce session or identity validation before granting access to sensitive data endpoints. Immediate remediation is required to restrict unauthorized access and protect against potential exploitation of this exposure.",
  "technicalDetails": "The vulnerability resides within the request handling logic of StifLi Backup Tools, where specific endpoints responsible for retrieving configuration or diagnostic data fail to implement proper authentication checks. In versions 2.2.7 and earlier, the application logic does not validate the security context of the incoming request, essentially treating all requests to these specific endpoints as trusted.\nThe root cause is an improper access control implementation within the internal routing or controller logic of the backup application. When a request is crafted to target sensitive resource paths, the application fails to invoke the authentication middleware, directly serving the data back to the requester. This indicates a design flaw where sensitive functions are exposed without verifying the caller's authorization token or session status.\nThe attack flow proceeds as follows: An unauthenticated attacker identifies the vulnerable target via network scanning or reconnaissance. Upon identifying the StifLi Backup Tool instance, the attacker sends an HTTP GET request to the known sensitive endpoints. Because the application lacks a mandatory authentication wrapper on these specific functions, the server process retrieves the requested resource—often containing sensitive configuration strings, database connection credentials, or encryption keys—from the local file system or memory and transmits the raw data back to the attacker in the response body. No special headers or complex payloads are required to trigger this behavior; standard web requests are sufficient.\nThis vulnerability is particularly severe due to its remote exploitation potential. Since the application does not require privileges to access these endpoints, the barrier to entry is minimal. Furthermore, the post-exploitation impact is extensive; once configuration data is obtained, an attacker may leverage the exposed credentials to gain unauthorized access to databases or associated infrastructure managed by the backup software. This secondary compromise can facilitate persistent access, data theft, or complete system takeover. The vulnerability persists across all deployments of the identified versions, regardless of the host OS, as the flaw is inherent to the application's implementation of access control."
}
CVE-2026-97240: StifLi Backup Unauthenticated Data Exposure (HIGH Severity, CVSS: 7.5) | Sceawere