CVE-2026-65938

Summary

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

Affected Software

VendorProductVersion RangeStatus
Progress Software CorporationWhatsUp Gold0 < 26.0.2affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization
  • CWE-602: CWE-602 Client-Side Enforcement of Server-Side Security

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References