Incorrect permission assignment for critical resource in WhatsUp Gold - CVE-2026-65940
Published: August 13, 2026
Vulnerability details
The vulnerability allows a local privileged user to write arbitrary files to a web-accessible location on the host server.
The vulnerability exists due to improper access control in filesystem permissions when accessing the host server filesystem. A local privileged user can write arbitrary files to write arbitrary files to a web-accessible location on the host server.