CVE ID :CVE-2026-44668 Published : May 26, 2026, 6:16 p.m. | 2ย hours, 7ย minutes ago Description :FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking for a valid session. Four action methods in BoilerPlateConfig perfo
Faction: Unauthenticated Read,
Exploit
CVE-2026-44668
MITRE CVE High
Refer to CVE-2026-44668 NVD advisory