CVE-2026-15733: remote command injection in WGDashboard WGDashboard

An attacker can execute arbitrary OS commands on WGDashboard (CVE-2026-15733), potentially gaining full control of affected installations. Versions on the 4.x branch are affected — 4.3.2 and earlier. Facts conflict on attacker requirements: the published CVSS vector indicates no privileges or user interaction are required, while an advisory description states the issue allows authenticated attackers to run commands; treat both possibilities when assessing exposure.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.1002
CWE
CWE-78
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a critical (CVSS 9.8) remote code execution via command injection with no available patch; prioritize reducing exposure and applying vendor guidance immediately.

What is CVE-2026-15733?

An attacker can execute arbitrary OS commands on WGDashboard (CVE-2026-15733), potentially gaining full control of affected installations. Versions on the 4.x branch are affected — 4.3.2 and earlier. Facts conflict on attacker requirements: the published CVSS vector indicates no privileges or user interaction are required, while an advisory description states the issue allows authenticated attackers to run commands; treat both possibilities when assessing exposure. The weakness is classified as CWE-78 (OS Command Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of WGDashboard WGDashboard are affected?

BRANCHAFFECTEDFIXED
4.x4.3.2 and earlier

Is CVE-2026-15733 being exploited?

There are no public reports of active exploitation or public exploit code as of 2026-09-29.

How to fix CVE-2026-15733

  1. Isolate internet-facing WGDashboard instances and restrict access to management interfaces.
  2. Apply vendor guidance and monitor vendor channels for a patch or official mitigation.
  3. Harden affected hosts: restrict network access, run with least-privilege accounts, and enable host-based detection and logging for suspicious command execution.
  4. Monitor logs and alerts for signs of exploitation and prepare to rebuild compromised systems if suspicious activity appears.

Frequently asked questions

Is CVE-2026-15733 being actively exploited?

No public reports of exploitation or public exploit code are known as of 2026-09-29; it is not listed in CISA's KEV catalog.

Which WGDashboard versions are affected by CVE-2026-15733?

WGDashboard 4.x branch is affected; specifically versions 4.3.2 and earlier are listed as vulnerable.

Is there a patch for CVE-2026-15733?

No—there is no patch available as of 2026-09-29; affected entries show no fixed versions.

Does CVE-2026-15733 require authentication?

Sources differ: the CVSS vector indicates no privileges required, while an advisory description states the vulnerability can be exploited by authenticated users; assume both scenarios until vendor clarification.

References