CVE-2026-94574
CVE-2026-94574
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execution via the use_askpass directive, potentially allowing local privilege escalation.
| Vendor | gnu wget (windows builds) |
| Product | wget |
| Published | Sep 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for gnu wget (windows builds) wget
Be the first to know when new unknown vulnerabilities affecting gnu wget (windows builds) wget are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
GNU Wget (Windows Builds) / Wget
0 โค 1.21.4