CVE-2026-44343

Source
https://cve.org/CVERecord?id=CVE-2026-44343
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44343.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44343
Aliases
  • GHSA-rrf5-q4fp-qvgm
Published
2026-05-12T16:39:46.817Z
Modified
2026-07-15T01:49:12.684133201Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
WGDashboard: Critical Vulnerability in 4.3.2
Details

WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file system without authentication. This vulnerability is fixed in 4.3.2.

Database specific
{
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44343.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/wgdashboard/wgdashboard

Affected ranges

Type
GIT
Repo
https://github.com/wgdashboard/wgdashboard
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:wgdashboard:wgdashboard:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.3.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

4.*
4.3.0.0-1
v1.*
v1.0
v1.0-beta.3
v1.0-beta.4
v1.0-beta.5
v1.1
v1.1.1
v1.1.2
v2.*
v2.0
v2.0.1-beta2
v2.1
v2.2
v2.2.1
v2.3.1
v3.*
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.6.1
v3.0.6.2
v4.*
v4.0
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.3.0
v4.2.3.0.1
v4.2.4
v4.2.5
v4.3.0
v4.3.0.1
v4.3.0.2
v4.3.0.3
v4.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44343.json"