Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-15734: WGDashboard 4.3.2 and earlier: Root Access via Malicious Input
CVE-2026-15734 · published 28 days ago
Summary
A security issue in WGDashboard allows an attacker with permission to inject malicious code, giving them full control over the system. This could lead to unauthorized changes, data theft, or complete system takeover. Update to the latest version of WGDashboard to fix this issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wgdashboard | wgdashboard | <= 4.3.2 |
Original advisory text
A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.
A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.
Severity
9.8
Critical
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-1336Improper Neutralization of Special Elements Used in a Template Engine
Timeline
Published6 Aug 2026
Updated3 Sep 2026
First seen6 Aug 2026
Monitor software like this
Free during beta