Sceawere
Vulnerability Detail
CVE-2026-97240UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
StifLi Backup Unauthenticated Data Exposure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Esteban
- Product
- StifLi Backup Tools
- Attack Type
- CWE-201 Insertion of Sensitive Information Into Sent Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-30T13:17:35.747Z",
"pubdate": "2026-09-30T13:17:35.747Z",
"executiveSummary": "StifLi Backup Tools versions 2.2.7 and earlier contain a critical vulnerability characterized as Unauthenticated Sensitive Data Exposure. The flaw allows remote, unauthenticated attackers to access and exfiltrate sensitive configuration files, backup metadata, or internal system data without requiring valid credentials.\nThis vulnerability poses a significant risk to organizational confidentiality and integrity. By bypassing authentication mechanisms, unauthorized parties can gain visibility into proprietary backup structures and potentially sensitive operational data. The attack surface is exposed directly via the network, necessitating no prior access to the underlying server environment. Given the nature of backup tools, successful exploitation may lead to full system compromise, exposure of credentials stored within backups, or the unauthorized acquisition of sensitive intellectual property.\nThe risk is exacerbated by the lack of defensive controls at the application entry point, which fails to enforce session or identity validation before granting access to sensitive data endpoints. Immediate remediation is required to restrict unauthorized access and protect against potential exploitation of this exposure.",
"technicalDetails": "The vulnerability resides within the request handling logic of StifLi Backup Tools, where specific endpoints responsible for retrieving configuration or diagnostic data fail to implement proper authentication checks. In versions 2.2.7 and earlier, the application logic does not validate the security context of the incoming request, essentially treating all requests to these specific endpoints as trusted.\nThe root cause is an improper access control implementation within the internal routing or controller logic of the backup application. When a request is crafted to target sensitive resource paths, the application fails to invoke the authentication middleware, directly serving the data back to the requester. This indicates a design flaw where sensitive functions are exposed without verifying the caller's authorization token or session status.\nThe attack flow proceeds as follows: An unauthenticated attacker identifies the vulnerable target via network scanning or reconnaissance. Upon identifying the StifLi Backup Tool instance, the attacker sends an HTTP GET request to the known sensitive endpoints. Because the application lacks a mandatory authentication wrapper on these specific functions, the server process retrieves the requested resource—often containing sensitive configuration strings, database connection credentials, or encryption keys—from the local file system or memory and transmits the raw data back to the attacker in the response body. No special headers or complex payloads are required to trigger this behavior; standard web requests are sufficient.\nThis vulnerability is particularly severe due to its remote exploitation potential. Since the application does not require privileges to access these endpoints, the barrier to entry is minimal. Furthermore, the post-exploitation impact is extensive; once configuration data is obtained, an attacker may leverage the exposed credentials to gain unauthorized access to databases or associated infrastructure managed by the backup software. This secondary compromise can facilitate persistent access, data theft, or complete system takeover. The vulnerability persists across all deployments of the identified versions, regardless of the host OS, as the flaw is inherent to the application's implementation of access control."
}