CVE-2026-27899Disclosure(wgportal / wireguard_portal)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wgportal wireguard_portal systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sending a single PUT request to their own user profile endpoint with `"IsAdmin": true` in the JSON body. After logging out and back in, the session picks up admin privileges from the database. When a user updates their own profile, the server parses the full JSON body into the user model, including the `IsAdmin` boolean field. A function responsible for preserving calculated or protected attributes pins certain fields to their database values (such as base model data, linked peer count, and authentication data), but it does not do this for `IsAdmin`. As a result, whatever value the client sends for `IsAdmin` is written directly to the database. After the exploit, the attacker has full admin access to the WireGuard VPN management portal. The problem was fixed in v2.1.3. The docker images for the tag 'latest' built from the master branch also include the fix.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wireguard_portal

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-26); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
wireguard_portal

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-26: 4Mentions · 2026-02-27: 1Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-26: 2Technical Details · 2026-02-26: 4Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 102-2602-2703-03
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-264
Disclosure3Patch1
2026-02-271
Disclosure1
2026-03-031
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27899 (CVSS:8.8, HIGH) is Analyzed. WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2...https://nvd.nist.gov/vuln/detail/CVE-2026-27899 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post briefly announces CVE-2026-27899 with a high CVSS score, noting it affects WireGuard Portal before version 2, but offers no further technical or actionable details.

    0000025
    173 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27899: CVE-2026-27899: The 'Are You God?' Checkbox in WireGuard Portal A critical Privilege Escalation vulnerability in h44z/wg-portal allows any authenticated user to promote themselves to Administrator by simply adding a JSON field to a pro... https://cvereports.com/reports/CVE-2026-27899

    Post summary

    A critical privilege escalation vulnerability in h44z/wg‑portal allows authenticated users to become administrators by adding a JSON field; no PoC, exploit code, patch, or active exploitation details are provided.

    0000037
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27899 WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can beco… https://www.cve.org/CVERecord?id=CVE-2026-27899

    Post summary

    CVE-2026-27899 allows authenticated non‑admin users to gain elevated privileges in WireGuard Portal before version 2.1.3, which addresses the issue.

    00000134
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27899 Privilege Escalation Vulnerability in WireGuard Portal Before Version 2.1.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27899

    Post summary

    A privilege escalation vulnerability (CVE-2026-27899) exists in WireGuard Portal versions prior to 2.1.3.

    0000031
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27899: HIGH] A security vulnerability in WireGuard Portal (wg-portal) allowed users to gain admin access by exploiting a PUT request. Update to version 2.1.3 for a fix.#cve,CVE-2026-27899,#cybersecurity https://cvefind.com/CVE-2026-27899

    Post summary

    The post reports a high‑severity vulnerability in WireGuard Portal that permits admin access through a PUT request and advises users to update to version 2.1.3 to remediate the issue.

    0000051
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27899** describes a critical flaw in the WireGuard Portal (wg-portal), a web-based management interface for WireGuard VPN servers. The vulnerability allows any authenticated user, regardless of their privileges, to escalate their permissions to full administrator level by manipulating their own user profile data. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2026-27899

    Post summary

    CVE-2026-27899 is a privilege‑escalation flaw in WireGuard Portal that allows authenticated users to gain full admin rights by altering their profile data. No PoC, exploit, or patch information is provided.

    0000039
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwgportalwireguard_portal---

Explore more