Local Code Execution Vulnerability in GNU Wget for Windows Builds
CVE-2026-94574
Currently unrated
What is CVE-2026-94574?
A local cross-user code execution vulnerability exists in GNU Wget specifically in Windows builds obtained from eternallybored.org. This flaw arises due to a hardcoded path to a configuration file (C:\msys64) that is writable by unprivileged users. By leveraging the use_askpass directive, attackers can execute arbitrary code, which may lead to local privilege escalation. This vulnerability emphasizes the need for robust security practices around file permissions and configurations in software.
Affected Version(s)
Wget 0 <= 1.21.4
