Vulnerabilities (CVE)

Filtered by vendor Wgportal
Filtered by product Wireguard Portal
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-27899 1 Wgportal 1 Wireguard Portal 2026-03-02 N/A 8.8 HIGH
WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sending a single PUT request to their own user profile endpoint with `"IsAdmin": true` in the JSON body. After logging out and back in, the session picks up admin privileges from the database. When a user updates their own profile, the server parses the full JSON body into the user model, including the `Is ...

Show More