Impact
The vulnerability is an unauthenticated remote code execution flaw in the internal report scheduling service of WhatsUp Gold. An attacker with network reach to the service can run arbitrary code under the IIS application service account. This flaw results from improper authentication checks (CWE‑306), insecure file path handling (CWE‑73), command injection (CWE‑918), and dynamic code execution (CWE‑94). Executing code as the IIS service account can give the attacker full control over the monitored system.
Affected Systems
Progress Software Corporation’s WhatsUp Gold software, versions released before 26.0.2, is affected. The flaw resides in the internal report scheduling component accessed over the network. Only systems running the vulnerable versions and exposing the scheduling service are at risk.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so public exploit data is unknown. The flaw can be exploited by an unauthenticated attacker who can reach the scheduling service, likely over a network port used by the application, and trigger arbitrary code execution. Successful exploitation would allow full compromise of the monitored host.
OpenCVE Enrichment