CVE-2026-72603

Source
https://cve.org/CVERecord?id=CVE-2026-72603
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72603.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72603
Published
2026-08-11T11:15:11.544Z
Modified
2026-08-13T04:02:58.630513889Z
Severity
  • 9.9 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
wg-easy wg-easy - OS Command Injection
Details

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution on the host.

Database specific
{
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72603.json",
    "cna_assigner": "TuranSec"
}
References

Affected packages

Git / github.com/wg-easy/wg-easy

Affected ranges

Type
GIT
Repo
https://github.com/wg-easy/wg-easy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "15.3.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v12.*
v12.0.0
v15.*
v15.0.0
v15.0.0-beta.1
v15.0.0-beta.10
v15.0.0-beta.11
v15.0.0-beta.12
v15.0.0-beta.13
v15.0.0-beta.2
v15.0.0-beta.3
v15.0.0-beta.4
v15.0.0-beta.5
v15.0.0-beta.6
v15.0.0-beta.7
v15.0.0-beta.8
v15.0.0-beta.9
v15.1.0
v15.2.0
v15.2.0-beta.1
v15.2.0-beta.2
v15.2.0-beta.3
v15.2.1
v15.2.2
v15.3.0
v15.3.0-beta.1
v15.3.0-beta.2
v15.3.0-beta.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72603.json"