Critical OS Command Injection Vulnerability in wg-easy 15.3.0 Disclosed

Critical OS Command Injection Vulnerability in wg-easy 15.3.0 Disclosed

First seen 12 Aug 2026, 02:41 UTC Feedlycve.akaoma.comcve.threatint.comnvd.nist.govvulners.com 92% similarity 78.0

Article Content

Browse articles
ThreatCluster

A severe OS command injection vulnerability (CVE-2026-72603) has been identified in wg-easy version 15.3.0. This flaw allows authenticated users with clients.create permission to inject newline-delimited WireGuard PostUp directives into the client name field, leading to arbitrary command execution with root privileges. The vulnerability arises because the client name is written to the WireGuard configuration file without neutralizing newline characters. Currently, there is no public proof-of-concept or evidence of exploitation. The CVSS base score assigned to this vulnerability is 9.9, indicating critical severity. Users are advised to update to a patched version and restrict permissions to trusted users. The vulnerability was published on August 11, 2026.

Key Points: • CVE-2026-72603 is a critical OS command injection vulnerability in wg-easy 15.3.0. • Authenticated users can execute arbitrary commands as root by exploiting this flaw. • Immediate updates and permission restrictions are recommended to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
CVE-2026-72603 published
The National Vulnerability Database published details of the OS command injection vulnerability in wg-easy 15.3.0.
nvd.nist.gov
2026-08-11
Security advisory released
GitHub Advisories released a security advisory regarding CVE-2026-72603, urging updates and permission restrictions.
Feedly

Community

Browse all →

Tracked Entities in This Story