Sceawere

Vulnerability Detail

CVE-2026-65939UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WhatsUp Gold Arbitrary File Creation

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
3h ago
Vendor
Progress Software Corporation
Product
WhatsUp Gold
Attack Type
CWE-434 Unrestricted upload of file with dangerous type
Vector String
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-08-12T16:17:13.797Z",
  "pubdate": "2026-08-12T16:17:13.797Z",
  "executiveSummary": "An arbitrary file creation vulnerability exists in WhatsUp Gold versions released before 2026.0.2.\nThe vulnerability allows a privileged threat actor to leverage the LogToFile action functionality to write files with arbitrary extensions directly into the Internet Information Services (IIS) web root.\nThe impact of this security flaw includes potential web application compromise, arbitrary code execution, or system integrity degradation depending on the content written and the permissions of the underlying worker process.\nThe affected product is WhatsUp Gold, specifically deployments running any software version prior to 2026.0.2.\nThe risk implications are significant as unauthorized file placement within the IIS web root can lead to downstream exploitation vectors such as web shell deployment or unauthorized resource modification.\nTo successfully execute this attack, the adversary must already possess elevated privileges within the application to configure and trigger logging actions.\nExploitation requirements are constrained by the necessity of authenticated administrative or privileged access, meaning the primary threat vector originates from insider threats, compromised administrative credentials, or chained privilege escalation vulnerabilities.",
  "technicalDetails": "The root cause of the vulnerability lies in insufficient input validation and path sanitization within the LogToFile action handling routines of WhatsUp Gold.\nThe vulnerable component is responsible for processing administrative logging configurations, specifically the parameters governing log file destination paths and file extensions.\nBecause the application fails to adequately restrict output paths or enforce strict validation on file extensions, an authenticated user with administrative privileges can supply malicious parameters that dictate where logs are written.\nThe exploitation method involves crafting a specialized LogToFile action configuration that targets the IIS web root directory.\nBy specifying an arbitrary file extension during the action creation process, the attacker bypasses intended logical boundaries designed to keep application logs contained within designated secure log directories.\nThe attack flow proceeds as follows: First, the privileged attacker authenticates to the WhatsUp Gold management interface. Second, the attacker navigates to the action configuration module and defines a new LogToFile action. Third, the attacker inputs parameters that specify a target path residing inside the active IIS web root and assigns a targeted file extension. Fourth, the application processes the action without proper boundary checks, writing the designated log content or payload directly to the specified location within the web-accessible directory structure.\nAuthentication requirements dictate that the actor must possess valid credentials capable of creating or modifying actions within the application.\nPrivilege requirements are explicitly high, requiring a privileged attacker role.\nNetwork exposure encompasses any deployment where the administrative interface is accessible, though the attack itself relies on internal application logic execution rather than raw remote code execution network listeners.\nThe payload behavior involves the persistence of attacker-controlled data into executable or interpretable web directories, which can subsequently be requested via HTTP/HTTPS protocols if the file format aligns with IIS-handled extensions.\nThe post-exploitation impact includes the potential staging of web shells or malicious scripts directly within the web root, facilitating further execution, lateral movement, or persistent access within the host environment."
}
CVE-2026-65939: WhatsUp Gold Arbitrary File Creation (MEDIUM Severity, CVSS: 6.8) - Sceawere