← Back to CVE search

CVE-2026-65938

WhatsUp Gold

Description

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

CVSS 4.3EPSS 0.161%Risk 0.44
View source
Published
2026-08-12 16:17:13
Affected versions
<2026.0.2
Type
Web application
Last modified
2026-08-12 18:18:06
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N