Persistent Script Injection Vulnerability in WhatsUp Gold by Progress
CVE-2026-65937

8HIGH

Key Information:

Vendor
CVE Published:
12 August 2026

What is CVE-2026-65937?

WhatsUp Gold versions released prior to 2026.0.2 are vulnerable to a persistent script injection flaw. An authenticated attacker can exploit this vulnerability to bypass frontend controls, allowing them to inject malicious script content that persists within the application. This can lead to severe consequences, including unauthorized actions and data manipulation, leveraging user trust in legitimate web application functionality.

Affected Version(s)

WhatsUp Gold Windows 0 < 26.0.2

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.