CVE-2026-65938EPSS p15.2%

CVE-2026-65938CVE-2026-65938

progress / whatsup_gold

Description

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

Scoring

CVSS 4.3 ()
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS0.25% probability of exploitation · percentile 15.2% · 2026-10-05T12:00:23Z
Last modified2026-09-02
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.