PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72603 wg-easy CVE debrief

An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. This critical vulnerability enables attackers with clients.create permission to achieve root code execution on the host. Administrators and users of wg-easy 15.3.0 should be aware of this vulnerability and take immediate action to remediate it. The CVE record was published on 2026-08-11T12:17:43.383Z and has not been modified since then. Evidence from the NVD and CVE Program records confirms the OS command injection vulnerability. Further verification is needed to determine the full scope of affected systems and versions. Additional review of system logs and configuration files is recommended to identify potential exploitation. The vulnerability allows users with clients.create permission to execute arbitrary OS commands as root, indicating a high priority for remediation.

Vendor
wg-easy
Product
Unknown
CVSS
CRITICAL 9.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-08-28
Advisory published
2026-08-11
Advisory updated
2026-08-28

Who should care

Administrators and users of wg-easy 15.3.0, especially those with clients.create permission, should be aware of this critical vulnerability and take immediate action to remediate it. Additionally, security teams and vulnerability management teams should prioritize this vulnerability for remediation due to its high severity and potential impact on system security.

Technical summary

The CVE-2026-72603 vulnerability is an OS command injection issue in wg-easy 15.3.0. Users with clients.create permission can inject newline-delimited WireGuard PostUp directives into the client name field, allowing execution of arbitrary commands as root. This vulnerability is particularly concerning due to its high CVSS score of 9.9 and the potential for attackers to gain root access to affected systems.

Defensive priority

This critical vulnerability allows users with clients.create permission to execute arbitrary OS commands as root, indicating a high priority for remediation.

Recommended defensive actions

  • Verify the version of wg-easy and check for vendor-provided patches or updates.
  • Restrict access to the clients.create permission to trusted users only.
  • Monitor system logs for suspicious activity related to wg-easy.
  • Consider implementing additional security controls, such as input validation and command whitelisting.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

Evidence from the NVD and CVE Program records confirms the OS command injection vulnerability in wg-easy 15.3.0. Further verification is needed to determine the full scope of affected systems and versions. The vulnerability allows users with clients.create permission to execute arbitrary OS commands as root, indicating a high priority for remediation. Additional review of system logs and configuration files is recommended to identify potential exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72603 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72603

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72603 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72603

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/wg-easy/wg-easy

    309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.