MEDIUM
h44z
CVE published 2026-09-17
CVE-2026-54551
A low-privilege user in WireGuard Portal versions 2.2.0 to 2.3.0 can enumerate peer public keys and monitor traffic statistics for peers belonging to other users, potentially leading to privacy issues and unauthorized monitoring. This issue arises from the authenticated GET /api/v0/ws statistics WebSocket subscribing to TopicPeerStatsUpdated and TopicInterfaceStatsUpdated and forwarding every TrafficDelta [truncated]