In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. | |
| Title | WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler. | |
| Weaknesses | CWE-22 CWE-434 CWE-73 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-08-12T17:06:21.779Z
Reserved: 2026-07-23T16:08:34.531Z
Link: CVE-2026-65939
No data.
Status : Received
Published: 2026-08-12T16:17:13.797
Modified: 2026-08-12T16:17:13.797
Link: CVE-2026-65939
No data.
OpenCVE Enrichment
No data.