DIRAS TAKE
Urgent: this is a critical (CVSS 9.8) remote code execution via command injection with no available patch; prioritize reducing exposure and applying vendor guidance immediately.
What is CVE-2026-15733?
An attacker can execute arbitrary OS commands on WGDashboard (CVE-2026-15733), potentially gaining full control of affected installations. Versions on the 4.x branch are affected — 4.3.2 and earlier. Facts conflict on attacker requirements: the published CVSS vector indicates no privileges or user interaction are required, while an advisory description states the issue allows authenticated attackers to run commands; treat both possibilities when assessing exposure. The weakness is classified as CWE-78 (OS Command Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of WGDashboard WGDashboard are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 4.x | 4.3.2 and earlier |
Is CVE-2026-15733 being exploited?
There are no public reports of active exploitation or public exploit code as of 2026-09-29.
How to fix CVE-2026-15733
- Isolate internet-facing WGDashboard instances and restrict access to management interfaces.
- Apply vendor guidance and monitor vendor channels for a patch or official mitigation.
- Harden affected hosts: restrict network access, run with least-privilege accounts, and enable host-based detection and logging for suspicious command execution.
- Monitor logs and alerts for signs of exploitation and prepare to rebuild compromised systems if suspicious activity appears.
Frequently asked questions
Is CVE-2026-15733 being actively exploited?
No public reports of exploitation or public exploit code are known as of 2026-09-29; it is not listed in CISA's KEV catalog.
Which WGDashboard versions are affected by CVE-2026-15733?
WGDashboard 4.x branch is affected; specifically versions 4.3.2 and earlier are listed as vulnerable.
Is there a patch for CVE-2026-15733?
No—there is no patch available as of 2026-09-29; affected entries show no fixed versions.
Does CVE-2026-15733 require authentication?
Sources differ: the CVSS vector indicates no privileges required, while an advisory description states the vulnerability can be exploited by authenticated users; assume both scenarios until vendor clarification.
References
- nvd.nist.gov/vuln/detail/CVE-2026-15733
- cve.org/CVERecord?id=CVE-2026-15733
- github.com/WGDashboard/WGDashboard
- github.com/Stuub/WGDashboard-v4.3.2-OS-Command-Injection-to-Root-RCE-PoC
- All WGDashboard CVEs on CVE Radar
- CVEs published in September 2026