OS Command Injection Vulnerability in wg-easy by wg-easy

⚠️ CVE-Referenzen: CVE-2026-72603
Wg-easy - Wg-easy - CRITICAL - CVE-2026-72603. An OS command injection vulnerability exists in wg-easy version 15.3.0, allowing users with 'clients.create' permissions to execute arbitrary commands as root. This vulnerability arises when newline-delimited WireGuard PostUp directives are injected into the client name field. Due to a lack of proper neutralization of newline characters, injected directives are written directly to the WireGuard configuration file. Consequently, these directives can be executed by wg-quick with root privileges, enabling an attacker to gain root-level code execution on affected hosts.
Quelle: securityvulnerability.io