OS Command Injection Vulnerability in wg-easy by wg-easy
CVE-2026-72603

9.9CRITICAL

Key Information:

Vendor

Wg-easy

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72603?

An OS command injection vulnerability exists in wg-easy version 15.3.0, allowing users with 'clients.create' permissions to execute arbitrary commands as root. This vulnerability arises when newline-delimited WireGuard PostUp directives are injected into the client name field. Due to a lack of proper neutralization of newline characters, injected directives are written directly to the WireGuard configuration file. Consequently, these directives can be executed by wg-quick with root privileges, enabling an attacker to gain root-level code execution on affected hosts.

Affected Version(s)

wg-easy 0 <= 15.3.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov
.