Cryptographic Weakness in WireGuard Easy VPN Software by WireGuard
CVE-2026-63089
9CRITICAL
What is CVE-2026-63089?
WireGuard Easy, an easy-to-use VPN software, has a vulnerability where it utilizes a cryptographically weak method for generating one-time link tokens. This flaw exposes the system to unauthenticated network attacks, as malicious actors can exploit the /cnf/:oneTimeLink URL without facing rate limiting. Consequently, they may be able to brute-force potential tokens, as the token generation process is constrained to a set of 1000 candidates. If successful, attackers could access a peer's PrivateKey and PresharedKey, enabling them to impersonate legitimate users of the VPN, significantly compromising network security.
Affected Version(s)
wg-easy 0 <= 15.3.0
wg-easy 0 <= 15.3.0
wg-easy 66b292b11bde3664f05ffb016c8082665d261ded
