CVE-2026-65938
WhatsUp Gold vulnerability analysis and mitigation

Overview

CVE-2026-65938 is an improper authorization vulnerability in the Scheduled Reports API of Progress Software's WhatsUp Gold network monitoring software. It affects all versions released before 2026.0.2 and allows any authenticated user to invoke restricted actions that should be limited to specific roles or permissions. The vulnerability was published on August 12, 2026, with a patch released in version 2026.0.2 on the same date. It carries a CVSS v3.1 base score of 4.3 (Medium) (Github Advisory, Progress Release Notes).

Technical details

The vulnerability is classified under CWE-602 (Client-Side Enforcement of Server-Side Security) and CWE-862 (Missing Authorization), indicating that the Scheduled Reports API fails to enforce proper server-side authorization checks, allowing authenticated users to bypass role-based access controls. An attacker positioned on the adjacent network who is authenticated to the WhatsUp Gold instance can send crafted API requests to the Scheduled Reports endpoint to invoke actions restricted to privileged roles. No special privileges are required beyond basic authentication, and no user interaction is needed to exploit the flaw. The attack vector is adjacent network (AV:A), meaning the attacker must have access to the same network segment as the WhatsUp Gold server (Github Advisory).

Impact

Successful exploitation allows any authenticated user to invoke restricted Scheduled Reports API actions that should be limited to higher-privileged roles, resulting in a low integrity impact with no confidentiality or availability impact. The scope is unchanged, meaning the vulnerability does not enable cross-component compromise or lateral movement beyond the WhatsUp Gold application itself. The primary risk is unauthorized manipulation of scheduled report configurations or triggering of restricted reporting operations by low-privileged users (Github Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The NVD SSVC assessment confirms exploitation is currently "none" and the vulnerability is not automatable. The EPSS score is approximately 0.161% (6th percentile), indicating a low probability of exploitation within the next 30 days. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog.

Exploitation steps

  1. Reconnaissance: Identify a WhatsUp Gold instance running a version prior to 2026.0.2 accessible on the adjacent network segment.
  2. Authentication: Obtain valid credentials for any user account on the WhatsUp Gold instance — even a low-privileged account is sufficient.
  3. API Enumeration: Enumerate the Scheduled Reports API endpoints available within the WhatsUp Gold web interface or REST API documentation.
  4. Craft Unauthorized Request: Send an authenticated HTTP request directly to a restricted Scheduled Reports API action that would normally require elevated privileges, bypassing the client-side authorization enforcement.
  5. Invoke Restricted Action: Due to the missing server-side authorization check, the API processes the request and executes the restricted action (e.g., creating, modifying, or deleting scheduled reports beyond the user's intended permission scope) (Github Advisory).

Indicators of compromise

  • Logs: WhatsUp Gold application logs showing authenticated low-privileged users invoking Scheduled Reports API endpoints associated with administrative or restricted actions.
  • Network: HTTP requests from unexpected or low-privileged user sessions targeting the Scheduled Reports API on the WhatsUp Gold server from adjacent network hosts.
  • Application: Unexpected creation, modification, or deletion of scheduled reports not attributable to administrative users; audit trail entries showing restricted API actions performed by non-admin accounts.

Mitigation and workarounds

Progress Software has released a patch in WhatsUp Gold version 2026.0.2 (released August 12, 2026), which addresses CVE-2026-65938 along with several other security fixes. Organizations should upgrade to version 2026.0.2 or later as the primary remediation step. As interim workarounds, administrators should restrict network access to the Scheduled Reports API to only authorized users and systems, and implement network segmentation to limit which hosts can reach the affected API endpoint (Progress Release Notes, Github Advisory).

Additional resources


SourceThis report was generated using AI

Related WhatsUp Gold vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65941HIGH8.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65937HIGH8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65940MEDIUM6.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65939MEDIUM6.8
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026
CVE-2026-65938MEDIUM4.3
  • WhatsUp Gold logoWhatsUp Gold
  • cpe:2.3:a:progress:whatsup_gold
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management