CVE-2026-65941

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-12 16:17

Updated : 2026-09-02 18:25


NVD link : CVE-2026-65941

Mitre link : CVE-2026-65941

CVE.ORG link : CVE-2026-65941


JSON object : View

Products Affected

progress

  • whatsup_gold
CWE
CWE-73

External Control of File Name or Path

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-306

Missing Authentication for Critical Function

CWE-918

Server-Side Request Forgery (SSRF)