Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-72603: WireGuard Easy: Malicious Commands Can Be Executed as Root

CVE-2026-72603 · published 24 days ago
Summary

An attacker with permission to create new clients in WireGuard Easy can inject malicious commands into the system by exploiting a vulnerability in the software. This allows them to execute commands with root privileges, potentially causing harm to the system. To mitigate this risk, ensure that only trusted users have permission to create new clients and keep WireGuard Easy up to date with the latest security patches.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
wg-easy wg-easy <= 15.3.0
Original advisory text
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directi...
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution on the host.
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published11 Aug 2026
Updated30 Aug 2026
First seen11 Aug 2026
Sources
CVE-2026-72603 · MITRE
Monitor software like this
Free during beta