OS Command Injection Vulnerability in wg-easy by wg-easy
CVE-2026-72603
9.9CRITICAL
What is CVE-2026-72603?
An OS command injection vulnerability exists in wg-easy version 15.3.0, allowing users with 'clients.create' permissions to execute arbitrary commands as root. This vulnerability arises when newline-delimited WireGuard PostUp directives are injected into the client name field. Due to a lack of proper neutralization of newline characters, injected directives are written directly to the WireGuard configuration file. Consequently, these directives can be executed by wg-quick with root privileges, enabling an attacker to gain root-level code execution on affected hosts.
Affected Version(s)
wg-easy 0 <= 15.3.0
