UNKNOWN NVD
CVE-2026-94574
A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys6
A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execution via the use_askpass directive, potentially allowing local privilege escalation.
References
- https://atos.net/en/lp/cybershield/a-tale-of-several-hijacks-and-what-it-taught-me-about-r
- https://eternallybored.org/misc/wget/
This unknown severity vulnerability was published on 2026-09-22 via NVD.
vulnfeed aggregates 13417 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.