Junglewise Threat Intelligence

CVE-2026-44343: WGDashboard unauthenticated host file system access

CVE-2026-44343 · Severity: critical · CVSS 9.8 · Published 2026-05-12

Executive brief

WGDashboard is a management interface for WireGuard VPNs. A critical security flaw allows unauthenticated attackers to access the underlying host's file system. This could lead to the theft of sensitive configuration files, encryption keys, or complete server compromise. Organizations using this dashboard to manage their VPN infrastructure are at high risk if the interface is exposed to the internet.

Technical details

WGDashboard prior to version 4.3.2 contains a critical vulnerability, identified as CWE-20 (Improper Input Validation), that allows for unauthenticated remote file system access. The flaw enables a network-based attacker to bypass authentication mechanisms and interact directly with the host's files. This is particularly dangerous for deployments where the dashboard is publicly accessible. The vulnerability has been addressed in version 4.3.2. Users unable to patch immediately are advised to restrict access to the dashboard to internal or trusted networks only.

Affected products

  • WGDashboard WGDashboard < 4.3.2

Timeline

  • 2026-04-27: advisory: Initial GitHub security advisory published
  • 2026-05-12: disclosed: CVE published to NVD
  • 2026-05-12: patched: Fix released in version 4.3.2

References