PT-2026-22074 · Unknown · Wireguard Portal

Gregtuc

·

Published

2026-02-24

·

Updated

2026-03-25

·

CVE-2026-27899

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WireGuard Portal versions prior to 2.1.3
Description WireGuard Portal, a web-based configuration portal for WireGuard server management, contains a flaw that allows authenticated non-admin users to escalate their privileges to full administrator level. This is achieved by sending a specially crafted PUT request to their own user profile endpoint, setting the IsAdmin field to true within the JSON body. The server does not properly validate or sanitize this input, directly writing the provided value to the database. Upon logging back in, the user session reflects the newly granted administrative privileges. An attacker gaining administrative access can read and modify user accounts, manage WireGuard peers, view interface configurations, disable user accounts, and access API tokens.
Recommendations Versions prior to 2.1.3 should be updated to version 2.1.3 or later. Ensure that docker images used are updated to the latest version built from the master branch, as it includes the fix.

Exploit

Fix

LPE

Improper Privilege Management

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04465
CVE-2026-27899
GHSA-5RMX-256W-8MJ9
GO-2026-4566
SUSE-SU-2026:1042-1

Affected Products

Wireguard Portal