OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94574

HIGH · CVSS 7.8 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A local cross-user code execution vulnerability in GNU wget for Windows allows unprivileged users to exploit a hardcoded writable configuration file path (C:\msys64) to execute arbitrary code through the use_askpass directive. This could lead to local privilege escalation, compromising the security of affected systems. Organizations using this version of wget should prioritize remediation to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94574
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Windows

Original NVD Description

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execution via the use_askpass directive, potentially allowing local privilege escalation.