CVE-2026-72603
wg-easy wg-easy - OS Command Injection
CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution on the host.
| CWE | CWE-78 |
| Vendor | wg-easy |
| Product | wg-easy |
| Published | Aug 11, 2026 |
| Last Updated | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for wg-easy wg-easy
Be the first to know when new critical vulnerabilities affecting wg-easy wg-easy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
wg-easy / wg-easy
0 โค 15.3.0
Credits
Bobur Abdugafforov