Impact
In WhatsUp Gold versions released before 2026.0.2, an improper authorization flaw in the Scheduled Reports API allows any authenticated user to invoke actions that should be restricted. These missing checks correspond to CWE‑602 and CWE‑862, meaning the system does not adequately limit operations within permitted bounds and fails to enforce proper authorization. The result is that a credentialed attacker can perform potentially sensitive monitoring tasks on the server, exposing data that should only be accessible to privileged users.
Affected Systems
Progress Software Corporation’s WhatsUp Gold network monitoring platform is affected. All installations of WhatsUp Gold prior to version 26.0.2 are vulnerable. The specific patch release that addresses the issue is 26.0.2, but the input does not list additional versions beyond that.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog. The vulnerability can be exploited by any authenticated user, typically through the network API used by the application. Attackers must first authenticate to the system; once logged in, they may invoke restricted report‑generation functions. The impact is unauthorized access to monitoring data rather than direct code execution or denial of service.
OpenCVE Enrichment