Description
WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /api/v0/ws statistics WebSocket in internal/app/api/v0/handlers/endpoint_websocket.go subscribes to TopicPeerStatsUpdated and TopicInterfaceStatsUpdated and forwards every TrafficDelta event without per-user authorization in handleWebsocket(). A low-privilege user can enumerate peer public keys through EntityId and monitor BytesReceived and BytesTransmitted values for peers belonging to other users. The same connection exposes interface_stats and interface names that the REST API limits to administrators. Tunnel content, AllowedIPs, and user identities remain authorization-gated. This issue is fixed in version 2.3.0.
Published: 2026-09-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized traffic statistics disclosure
Action: Patch
AI Analysis

Impact

WireGuard Portal (wg-portal) is a web‑based configuration tool for managing WireGuard servers. An authenticated WebSocket endpoint /api/v0/ws is intended to provide per‑user statistics. However, in versions 2.2.0 through prior to 2.3.0, the code forwards all TrafficDelta events for both peer and interface statistics without performing per‑user authorization checks. As a result, a low‑privilege user can subscribe to the WebSocket and receive bytes received/transmitted data, peer public keys, interface names and other traffic metrics that belong to other users. This leakage exposes the volume and identity of network traffic, allowing an attacker to map active connections and infer usage patterns. The vulnerability is an instance of missing per‑user authorization, classified as CWE‑285. It does not expose any cryptographic material or raw tunnel traffic.

Affected Systems

The defect is specific to the h44z wg‑portal product, versions 2.2.0 through any 2.2.x release before the fix. The vulnerability was addressed in the 2.3.0 release, as documented in the GitHub commit and release notes. All installations running an affected version with the WebSocket statistics feature enabled are susceptible. Protection requires upgrading to v2.3.0 or later or disabling the statistics endpoint for non‑administrator accounts.

Risk and Exploitability

The publicly available CVSS metric assigns a 4.3 score, indicating low severity. EPSS is reported at < 1 %, suggesting a very low chance of exploitation. The vulnerability is not listed in the CISA KEV catalog, reinforcing its lower profile. The attack requires an authenticated session with a non‑administrator account, so the threat surface is limited to users with legitimate portal access. While the information disclosed is non‑critical data, such as traffic volumes and peer identifiers, it can still aid reconnaissance or privacy‑breach objectives. Because the issue is not remote code execution and occurs only within authenticated users, an organization can realistically mitigate risk through patching or endpoint restriction.

Generated by OpenCVE AI on September 19, 2026 at 03:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest wg‑portal release (v2.3.0 or newer) that implements per‑user authorization for WebSocket statistics.
  • If immediate upgrading is not possible, restrict access to the /api/v0/ws endpoint so that only administrator accounts can establish a WebSocket session, either by adjusting the portal’s role configuration or by applying reverse‑proxy ACLs.
  • As a temporary measure, block or disable the statistics WebSocket for all non‑administrator users using firewall rules or proxy configuration until the patch is applied.

Generated by OpenCVE AI on September 19, 2026 at 03:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared H44z
H44z wg-portal
Vendors & Products H44z
H44z wg-portal

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /api/v0/ws statistics WebSocket in internal/app/api/v0/handlers/endpoint_websocket.go subscribes to TopicPeerStatsUpdated and TopicInterfaceStatsUpdated and forwards every TrafficDelta event without per-user authorization in handleWebsocket(). A low-privilege user can enumerate peer public keys through EntityId and monitor BytesReceived and BytesTransmitted values for peers belonging to other users. The same connection exposes interface_stats and interface names that the REST API limits to administrators. Tunnel content, AllowedIPs, and user identities remain authorization-gated. This issue is fixed in version 2.3.0.
Title WireGuard Portal: Authenticated WebSocket /api/v0/ws broadcasts all peers' and interfaces' traffic stats to every user (missing per-user authorization)
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T21:00:54.300Z

Reserved: 2026-06-15T19:04:14.456Z

Link: CVE-2026-54551

cve-icon Vulnrichment

Updated: 2026-09-21T21:00:49.064Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T18:16:46.883

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses