云虫漏洞库

CVE-2026-72603 - An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves roo - 漏洞详情

漏洞编号:CVE-2026-72603

风险等级:危急

漏洞来源:CVE

CVE 编号:CVE-2026-72603

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-78

发布/更新时间:2026-08-11 / 2026-08-28

漏洞描述

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution on the host.

相关链接

相关漏洞

« 返回首页