Sceawere

Vulnerability Detail

CVE-2026-65938UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WhatsUp Gold Improper Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Progress Software Corporation
Product
WhatsUp Gold
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-12T16:17:13.667Z",
  "pubdate": "2026-08-12T16:17:13.667Z",
  "executiveSummary": "An improper authorization vulnerability has been identified in the Scheduled Reports API of WhatsUp Gold in versions released prior to 2026.0.2. This security flaw enables any authenticated user to invoke restricted administrative or privileged actions that should normally be blocked based on role-based access control policies. The primary impact of this vulnerability involves the potential compromise of sensitive system functionality and unauthorized data access within the affected management plane. Risk implications are elevated as the attack surface includes authenticated low-privileged users capable of escalating their operational scope via API manipulation. Attacker capabilities rely on possessing valid user credentials to interact directly with the vulnerable API endpoints, thereby bypassing intended functional constraints. Exploitation requirements mandate that the threat actor has established an authenticated session within the application prior to dispatching malicious or unauthorized API requests.",
  "technicalDetails": "The vulnerability resides within the Scheduled Reports API component of WhatsUp Gold, affecting all software iterations deployed prior to version 2026.0.2. The root cause stems from a failure in the application logic to adequately enforce proper authorization checks upon incoming API requests. Specifically, the backend endpoints responsible for handling scheduled report operations fail to validate whether the requesting user possesses the necessary administrative privileges or functional roles before executing sensitive actions. The attack flow begins when an attacker with standard or low-privileged authentication crafts an HTTP request targeting the restricted Scheduled Reports API functions. Because the vulnerable component lacks robust access control validation, the server processes the incoming request and performs the restricted action on behalf of the user. Network exposure includes any interface capable of routing HTTP or HTTPS traffic to the vulnerable WhatsUp Gold API endpoints. Authentication requirements are strictly limited to possessing a valid user session, meaning any standard account can exploit the oversight. Privilege requirements are effectively bypassed through this logical flaw, allowing low-privileged users to perform high-privilege operations. Post-exploitation impact encompasses unauthorized execution of restricted system routines, potential exposure of sensitive reporting data, and disruption of scheduled monitoring workflows. Remediation requires updating the affected deployment to version 2026.0.2 or later, where proper authorization logic is enforced across all API endpoints."
}
CVE-2026-65938: WhatsUp Gold Improper Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere