CyberRota Analysis
AI-GeneratedA missing authorization vulnerability in the wgagent management daemon allows low-privileged authenticated users, such as read-only or guest administrators, to crash the wgagent process and access arbitrary files through specially crafted API requests. This could lead to unauthorized data exposure and service disruption. Organizations using the wgagent management daemon should prioritize remediation to mitigate potential exploitation risks.
Original NVD Description
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
Related CVEs
Other vulnerabilities affecting the same vendor(s)