CVE-2026-44668
FACTION, a framework for generating and sharing penetration testing reports, had a flaw that let anyone without a login read, modify, deactivate, or delete any boilerplate template. The issue was caused by missing session checks in several components. The problem is fixed in version 1.8.3.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
FACTION PenTesting Report Generation and Collaboration Framework, versions earlier than 1.8.3, used by security teams and organizations that rely on the tool for report creation.
Real-world impact
An attacker who can reach the application can delete or alter report templates, effectively destroying or corrupting the reporting infrastructure. This could lead to loss of critical data, misrepresentation of findings, and disruption of security operations.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited from anywhere, requires no authentication, and gives the attacker full control over confidentiality, integrity, and availability of the templates. Because the attacker can completely delete or modify data, the impact is considered critical.
What to do about it
- 01Upgrade FACTION to version 1.8.3 or later.
- 02Restart the application to apply the update.
NVD-referenced vendor advisory
Timeline
- May 26, 2026 · May 26, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 15d agoAdvisory updatedThe NVD record was last revised.
- Jul 20, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.