OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-90441

HIGH · CVSS 8.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A missing authorization vulnerability in the wgagent management daemon allows low-privileged authenticated users, such as read-only or guest administrators, to crash the wgagent process and access arbitrary files through specially crafted API requests. This poses a significant security risk as it can lead to unauthorized data exposure and service disruption. Organizations utilizing the wgagent management daemon should prioritize remediation to mitigate potential exploitation.

CVE
CVE-2026-90441
Severity
HIGH
CVSS
8.1
EPSS
0.23%

Original NVD Description

A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.

Related CVEs

Other vulnerabilities affecting the same vendor(s)