Executive brief
WhatsUp Gold is a network monitoring and management platform used to track IT infrastructure health and performance. A privileged attacker can exploit a flaw in the LogToFile action feature to create files with arbitrary extensions in the IIS web root directory, potentially enabling code execution or data exposure on the monitoring server.
Technical details
The vulnerability exists in the LogToFile action creation mechanism in WhatsUp Gold versions prior to 2026.0.2. A privileged (authenticated) attacker can specify an arbitrary file extension when creating a LogToFile action, allowing files to be written to locations within the IIS web root without proper validation. This could permit an attacker to write executable files (e.g., .aspx, .asp) or other web-accessible content that could be accessed via HTTP. The attack requires prior authentication/elevated privileges within WhatsUp Gold. Patches are available in version 2026.0.2 and later.
Affected products
- Progress WhatsUp Gold before 2026.0.2
Timeline
- 2026-08-12: disclosed
- 2026-08-12: patched: Fixed in version 2026.0.2