Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85688— TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer

Quick assessment

Affected
TEN-framework ten-framework
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TEN framework是TEN framework组织的一个支持多场景的开发框架。 TEN framework 0.11.71版本存在授权问题漏洞,该漏洞源于TMAN Designer file-content API端点缺乏身份验证导致任意文件读写,攻击者可向/api/designer/v1/file-content端点提交POST和PUT请求,读取任意文件或向系统路径写入恶意内容,从而通过authorized_keys、cron文件或可执行graph文件实现代码执行。

CVSS 9.8 · Critical EPSS 1.47% · P73

Public Exploits 1

Affected Version Matrix 1

VendorProduct Version RangeStatus
TEN-framework ten-framework ≤ 0.11.71 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85688

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer
Source: CVE Program / CVE List V5
Vulnerability Description
TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
TEN framework 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TEN framework是TEN framework组织的一个支持多场景的开发框架。 TEN framework 0.11.71版本存在授权问题漏洞,该漏洞源于TMAN Designer file-content API端点缺乏身份验证导致任意文件读写,攻击者可向/api/designer/v1/file-content端点提交POST和PUT请求,读取任意文件或向系统路径写入恶意内容,从而通过authorized_keys、cron文件或可执行graph文件实现代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
TEN-framework ten-framework 0 ~ 0.11.71 -

II. Public POCs for CVE-2026-85688

# POC Description Source Link Shenlong Link
1 TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints, letting attackers read or write arbitrary files and execute code. The exploit requires no authentication. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-85688.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85688

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85688 (1)

Proof of Concept for CVE-2026-85688 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85688

No comments yet


Leave a comment