CVE-2026-65938EPSS p5.8%

CVE-2026-65938CVE-2026-65938

Description

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.

Scoring

CVSS 4.3 ()
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS0.16% probability of exploitation · percentile 5.8% · 2026-08-13T12:03:51Z
Last modified2026-08-12
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.