All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-65938
MEDIUMpublished 2026-08-12 16:17 UTC · 11 hours ago · modified 2026-08-12 18:18 UTC
4.3
CVSS / 10
// description
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
// weaknesses (CWE)
- CWE-602
- CWE-862