Executive brief
WhatsUp Gold is a network monitoring and management platform used by enterprises to oversee IT infrastructure. A vulnerability in the Scheduled Reports API allows any authenticated user to perform actions that should be restricted to higher-privileged users, potentially allowing them to create, modify, or delete reports inappropriately and access sensitive monitoring data they should not see.
Technical details
The Scheduled Reports API in WhatsUp Gold versions prior to 2026.0.2 contains an improper authorization flaw where access controls fail to properly enforce role-based restrictions. Any authenticated user can invoke API endpoints that should be restricted to administrators or specific user roles. This vulnerability requires prior authentication to the WhatsUp Gold application, so an attacker must have valid credentials. An exploited flaw allows an authenticated attacker to perform unauthorized administrative actions against scheduled reports, potentially including creation, modification, deletion, or viewing of sensitive reports across the organization. The vulnerability was patched in version 2026.0.2, released on August 12, 2026.
Affected products
- Progress WhatsUp Gold before 2026.0.2
Timeline
- 2026-08-12: disclosed
- 2026-08-12: patched: Fixed in version 2026.0.2