CRITICAL 9.9 NVD

CVE-2026-72603

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newli

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution on the host.

References

Published: 2026-08-11 · Source: NVD · Feed updated: 2026-08-11
This critical severity vulnerability with a CVSS score of 9.9 was published on 2026-08-11 via NVD.

Risk Timeline

CVE Disclosed2026-08-11 · -1 days ago

Remediation Resources

vulnfeed aggregates 9850 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.