Aller au contenu principal
CRITICAL

CVE-2026-72603

CVSS v3

9.9

CRITICAL

Score EPSS

2.1 %

probabilité d’exploitation

CISA KEV

Non

exploitation connue

Exploitation

statut SSVC

Description

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution

Détails techniques

Vecteur CVSS v3
3.1
Publiée le
2026-08-11
Dernière modification
2026-08-11

Questions fréquentes

Qu’est-ce que CVE-2026-72603 ?

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution

CVE-2026-72603 est-elle activement exploitée ?

Aucune exploitation active de CVE-2026-72603 n’est confirmée. Le score EPSS est de 2.1 %, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2026-72603 ?

CVE-2026-72603 a un score de base CVSS v3 de 9.9 (gravité CRITICAL), avec le vecteur 3.1.

CVE-2026-72603 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite