
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65938 is an improper authorization vulnerability in the Scheduled Reports API of Progress Software's WhatsUp Gold network monitoring software. It affects all versions released before 2026.0.2 and allows any authenticated user to invoke restricted actions that should be limited to specific roles or permissions. The vulnerability was published on August 12, 2026, with a patch released in version 2026.0.2 on the same date. It carries a CVSS v3.1 base score of 4.3 (Medium) (Github Advisory, Progress Release Notes).
The vulnerability is classified under CWE-602 (Client-Side Enforcement of Server-Side Security) and CWE-862 (Missing Authorization), indicating that the Scheduled Reports API fails to enforce proper server-side authorization checks, allowing authenticated users to bypass role-based access controls. An attacker positioned on the adjacent network who is authenticated to the WhatsUp Gold instance can send crafted API requests to the Scheduled Reports endpoint to invoke actions restricted to privileged roles. No special privileges are required beyond basic authentication, and no user interaction is needed to exploit the flaw. The attack vector is adjacent network (AV:A), meaning the attacker must have access to the same network segment as the WhatsUp Gold server (Github Advisory).
Successful exploitation allows any authenticated user to invoke restricted Scheduled Reports API actions that should be limited to higher-privileged roles, resulting in a low integrity impact with no confidentiality or availability impact. The scope is unchanged, meaning the vulnerability does not enable cross-component compromise or lateral movement beyond the WhatsUp Gold application itself. The primary risk is unauthorized manipulation of scheduled report configurations or triggering of restricted reporting operations by low-privileged users (Github Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The NVD SSVC assessment confirms exploitation is currently "none" and the vulnerability is not automatable. The EPSS score is approximately 0.161% (6th percentile), indicating a low probability of exploitation within the next 30 days. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog.
Progress Software has released a patch in WhatsUp Gold version 2026.0.2 (released August 12, 2026), which addresses CVE-2026-65938 along with several other security fixes. Organizations should upgrade to version 2026.0.2 or later as the primary remediation step. As interim workarounds, administrators should restrict network access to the Scheduled Reports API to only authorized users and systems, and implement network segmentation to limit which hosts can reach the affected API endpoint (Progress Release Notes, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."