[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Security advisory: Pre-authentication RCE in Plastic SCM (Unity Version Control On-Prem) 11.0.16.10303 (Unity Technologies)
- To: fulldisclosure@xxxxxxxxxxxx
- Subject: [FD] Security advisory: Pre-authentication RCE in Plastic SCM (Unity Version Control On-Prem) 11.0.16.10303 (Unity Technologies)
- From: disclosure via Fulldisclosure <fulldisclosure@xxxxxxxxxxxx>
- Date: Mon, 3 Aug 2026 03:36:45 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Plastic
SCM (Unity Version Control On-Prem) 11.0.16.10303 (Unity Technologies). The
research is published and a proof-of-concept is available.
Pre-authentication RCE (CVSS 9.8, pre-authentication)
Plastic SCM ships a self-developed binary version-control protocol on port
8087, reachable by default on 0.0.0.0. Under the default NameWorkingMode, the
server validates only that a client-declared username maps to a local OS
account and never checks a password; LocalGroupSEIDProvider.CheckPassword is an
empty no-op. Combined with a default EVERYBODY ACL that grants ALL_PERMISSIONS
(including mktrigger) to any name-only-authenticated user, an unauthenticated
attacker can declare an administrative username (leaked unauthenticated via
GetRepositoryServerInfo), create a server-side trigger whose Path is fully
attacker-controlled, and trigger it with a repository operation.
TriggerProcess.ExecuteTrigger feeds the Path straight into Process.Start as the
FileName with no sandbox, path allowlist, or signature check, yielding RCE as
the plasticd service account (Linux: plasticscm uid=217; Windows: local
Administrator). The only non-network prerequisite is one local OS username,
which the pro
tocol itself leaks.
Impact: Full compromise of the version-control server and all repositories, and
arbitrary command execution as the plasticd service account; the attacker can
read source code and repository metadata, create triggers, alter repositories,
and persist access.
Advisory: https://0day-rubbish.com/blog/plastic-scm-unauth-8087-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/