๐Ÿ” CVE Alert

CVE-2026-94574

UNKNOWN 0.0

CVE-2026-94574

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execution via the use_askpass directive, potentially allowing local privilege escalation.

Vendor gnu wget (windows builds)
Product wget
Published Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for gnu wget (windows builds) wget

Be the first to know when new unknown vulnerabilities affecting gnu wget (windows builds) wget are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

GNU Wget (Windows Builds) / Wget
0 โ‰ค 1.21.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
eternallybored.org: https://eternallybored.org/misc/wget/ atos.net: https://atos.net/en/lp/cybershield/a-tale-of-several-hijacks-and-what-it-taught-me-about-runtime-driven-testing