PatchSiren cyber security CVE debrief
CVE-2026-72603 wg-easy CVE debrief
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. This critical vulnerability enables attackers with clients.create permission to achieve root code execution on the host. Administrators and users of wg-easy 15.3.0 should be aware of this vulnerability and take immediate action to remediate it. The CVE record was published on 2026-08-11T12:17:43.383Z and has not been modified since then. Evidence from the NVD and CVE Program records confirms the OS command injection vulnerability. Further verification is needed to determine the full scope of affected systems and versions. Additional review of system logs and configuration files is recommended to identify potential exploitation. The vulnerability allows users with clients.create permission to execute arbitrary OS commands as root, indicating a high priority for remediation.
- Vendor
- wg-easy
- Product
- Unknown
- CVSS
- CRITICAL 9.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-08-28
Who should care
Administrators and users of wg-easy 15.3.0, especially those with clients.create permission, should be aware of this critical vulnerability and take immediate action to remediate it. Additionally, security teams and vulnerability management teams should prioritize this vulnerability for remediation due to its high severity and potential impact on system security.
Technical summary
The CVE-2026-72603 vulnerability is an OS command injection issue in wg-easy 15.3.0. Users with clients.create permission can inject newline-delimited WireGuard PostUp directives into the client name field, allowing execution of arbitrary commands as root. This vulnerability is particularly concerning due to its high CVSS score of 9.9 and the potential for attackers to gain root access to affected systems.
Defensive priority
This critical vulnerability allows users with clients.create permission to execute arbitrary OS commands as root, indicating a high priority for remediation.
Recommended defensive actions
- Verify the version of wg-easy and check for vendor-provided patches or updates.
- Restrict access to the clients.create permission to trusted users only.
- Monitor system logs for suspicious activity related to wg-easy.
- Consider implementing additional security controls, such as input validation and command whitelisting.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
Evidence from the NVD and CVE Program records confirms the OS command injection vulnerability in wg-easy 15.3.0. Further verification is needed to determine the full scope of affected systems and versions. The vulnerability allows users with clients.create permission to execute arbitrary OS commands as root, indicating a high priority for remediation. Additional review of system logs and configuration files is recommended to identify potential exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72603 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72603
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72603 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72603
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/wg-easy/wg-easy
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.