Cryptographic Weakness in WireGuard Easy VPN Software by WireGuard
CVE-2026-63089

9CRITICAL

Key Information:

Vendor

Wg-easy

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-63089?

WireGuard Easy, an easy-to-use VPN software, has a vulnerability where it utilizes a cryptographically weak method for generating one-time link tokens. This flaw exposes the system to unauthenticated network attacks, as malicious actors can exploit the /cnf/:oneTimeLink URL without facing rate limiting. Consequently, they may be able to brute-force potential tokens, as the token generation process is constrained to a set of 1000 candidates. If successful, attackers could access a peer's PrivateKey and PresharedKey, enabling them to impersonate legitimate users of the VPN, significantly compromising network security.

Affected Version(s)

wg-easy 0 <= 15.3.0

wg-easy 0 <= 15.3.0

wg-easy 66b292b11bde3664f05ffb016c8082665d261ded

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.