Executive brief
FACTION, a collaboration framework used by security teams to generate penetration testing reports, contains a flaw that allows unauthorized individuals to access the system without a password. An attacker can remotely read, modify, or permanently delete report templates, which often contain sensitive proprietary testing methodologies and confidential security findings. This could lead to the loss of critical intellectual property or the silent injection of malicious or false information into client-facing security reports.
Technical details
A missing authentication vulnerability exists in FACTION's AccessControlInterceptor, which serves as the primary security gate for Struts2 actions. The interceptor fails to validate sessions before calling invocation.invoke(), allowing requests to reach backend action methods regardless of authentication status. While many methods implement local session checks, four specific endpoints in BoilerPlateConfig (tempDelete, tempActive, globalSaveTemplate, and searchTemplateDetail) do not. A remote, unauthenticated attacker can exploit this to perform CRUD operations on boilerplate templates by iterating through sequential integer IDs. This allows for the unauthorized disclosure of private templates, modification of global templates used in reporting, or permanent deletion of the template database. The issue is resolved in version 1.8.3 by enforcing session validation within the interceptor and adding local checks to the affected methods.
Affected products
- factionsecurity FACTION < 1.8.3
Timeline
- 2026-05-05: patched: Version 1.8.3 released
- 2026-05-26: advisory: GitHub Security Advisory published
- 2026-05-26: disclosed: CVE-2026-44668 published to NVD