๐Ÿ” CVE Alert

CVE-2026-72603

CRITICAL 9.9

wg-easy wg-easy - OS Command Injection

CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution on the host.

CWE CWE-78
Vendor wg-easy
Product wg-easy
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for wg-easy wg-easy

Be the first to know when new critical vulnerabilities affecting wg-easy wg-easy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

wg-easy / wg-easy
0 โ‰ค 15.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/wg-easy/wg-easy

Credits

Bobur Abdugafforov