[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Security advisory: Pre-authentication RCE in Wyn Enterprise 9.1.00145.0 (Mescius (GrapeCity))
- To: fulldisclosure@xxxxxxxxxxxx
- Subject: [FD] Security advisory: Pre-authentication RCE in Wyn Enterprise 9.1.00145.0 (Mescius (GrapeCity))
- From: disclosure via Fulldisclosure <fulldisclosure@xxxxxxxxxxxx>
- Date: Tue, 18 Aug 2026 06:04:17 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Wyn
Enterprise 9.1.00145.0 (Mescius (GrapeCity)). The research is published and a
proof-of-concept is available.
Pre-authentication RCE (CVSS 9.8, pre-authentication)
Wyn Enterprise 9.1.00145.0 exposes an unauthenticated root RCE chain of three
vulnerabilities: JWT signature validation is skipped (parse-only ReadToken)
with a hardcoded integration client secret, producing an unauthenticated
10-year admin reference token; the import endpoint allows a zip-slip arbitrary
file write (a malicious DLL can be dropped into the security-provider folder);
and the security-provider loader scans DLLs and calls Activator.CreateInstance
on the parameterless constructor, running as root. All three are reachable
without credentials in the default configuration. Dynamically verified with
root RCE.
Impact: Full host compromise as root (the dotnet container process); the
attacker can read the host filesystem, execute arbitrary commands, and take
full control of the Wyn server.
Advisory: https://0day-rubbish.com/blog/wyn-enterprise-unauth-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/