PatchSiren

h44z CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM h44z CVE published 2026-09-17

CVE-2026-54551

A low-privilege user in WireGuard Portal versions 2.2.0 to 2.3.0 can enumerate peer public keys and monitor traffic statistics for peers belonging to other users, potentially leading to privacy issues and unauthorized monitoring. This issue arises from the authenticated GET /api/v0/ws statistics WebSocket subscribing to TopicPeerStatsUpdated and TopicInterfaceStatsUpdated and forwarding every TrafficDelta [truncated]