Description
A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.
Published: 2026-08-06
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw in WGDashboard allows an authenticated adversary to run arbitrary shell commands with root privileges. The flaw is triggered by user-supplied input that is passed directly to the operating system shell, creating a full remote code execution vector. This can lead to complete compromise of the affected system, exposing all data and services and enabling further lateral movement.

Affected Systems

The vulnerability affects the WGDashboard application, specifically all releases 4.2.3 and earlier. Users running these versions are susceptible to exploitation.

Risk and Exploitability

The CVSS score is not publicly listed, and EPSS data is unavailable, indicating that the vulnerability is recognized but the exact likelihood of exploitation in the wild is unknown. Because the attack requires authenticated access to the dashboard, an attacker must first obtain valid credentials or prompt an existing authenticated user to trigger the injection. Once in, the attacker can execute commands as root, causing a catastrophic compromise of confidentiality, integrity, and availability. The vulnerability is not currently listed in CISA’s KEV catalog, but the potential impact warrants vigilance.

Generated by OpenCVE AI on August 6, 2026 at 23:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WGDashboard to version 4.3.2 or later
  • Restrict credential usage by enforcing strong, unique passwords and limiting access to trusted users
  • Disable or sandbox the OS command execution feature, or run the application under a non‑root account when possible
  • Implement logging and monitoring of command execution activity to detect suspicious behavior

Generated by OpenCVE AI on August 6, 2026 at 23:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Wgdashboard
Wgdashboard wgdashboard
Vendors & Products Wgdashboard
Wgdashboard wgdashboard

Fri, 07 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.
Title WGDashboard Remote Code Execution vulnerability
References

Subscriptions

Wgdashboard Wgdashboard
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-08-06T20:00:26.421Z

Reserved: 2026-07-14T13:44:05.071Z

Link: CVE-2026-15733

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T00:00:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')