From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:04:17 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Wyn Enterprise 9.1.00145.0 (Mescius (GrapeCity)).
The research is published and a proof-of-concept is available.
Pre-authentication RCE (CVSS 9.8, pre-authentication)
Wyn Enterprise 9.1.00145.0 exposes an unauthenticated root RCE chain of three vulnerabilities: JWT signature validation
is skipped (parse-only ReadToken) with a hardcoded integration client secret, producing an unauthenticated 10-year
admin reference token; the import endpoint allows a zip-slip arbitrary file write (a malicious DLL can be dropped into
the security-provider folder); and the security-provider loader scans DLLs and calls Activator.CreateInstance on the
parameterless constructor, running as root. All three are reachable without credentials in the default configuration.
Dynamically verified with root RCE.
Impact: Full host compromise as root (the dotnet container process); the attacker can read the host filesystem, execute
arbitrary commands, and take full control of the Wyn server.
Advisory: https://0day-rubbish.com/blog/wyn-enterprise-unauth-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- Security advisory: Pre-authentication RCE in Wyn Enterprise 9.1.00145.0 (Mescius (GrapeCity)) disclosure via Fulldisclosure (Aug 17)