PatchSiren

wg-easy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL wg-easy CVE published 2026-08-11

CVE-2026-72603

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick wi [truncated]

CRITICAL wg-easy CVE published 2026-07-16

CVE-2026-63089

WireGuard Easy through version 15.3.0 is vulnerable to a cryptographically weak one-time link token generation vulnerability. This vulnerability allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a keyspace of at most 1000 candidate tokens per client ID. The token is computed using CRC32 over a random value constrained to 0-999. Attackers can enumerate candidat [truncated]