OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-86136

HIGH · CVSS 8.1 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A missing authorization vulnerability in the wgagent management daemon allows low-privileged authenticated users, such as read-only or guest administrators, to crash the wgagent process and access arbitrary files through specially crafted API requests. This could lead to unauthorized data exposure and service disruption. Organizations using the wgagent management daemon should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-86136
Severity
HIGH
CVSS
8.1
EPSS
0.30%

Original NVD Description

A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.

Related CVEs

Other vulnerabilities affecting the same vendor(s)