CVE-2026-54551: WireGuard Portal: Authenticated WebSocket /api/v0/ws broadcasts all peers' and interfaces' traffic stats to every user (missing per-user authorization)

Published Sep 17, 2026
·
Updated

WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /api/v0/ws statistics WebSocket in internal/app/api/v0/handlers/endpointwebsocket.go subscribes to TopicPeerStatsUpdated and TopicInterfaceStatsUpdated and forwards every TrafficDelta event without per-user authorization in handleWebsocket(). A low-privilege user can enumerate peer public keys through EntityId and monitor BytesReceived and BytesTransmitted values for peers belonging to other users. The same connection exposes interfacestats and interface names that the REST API limits to administrators. Tunnel content, AllowedIPs, and user identities remain authorization-gated. This issue is fixed in version 2.3.0.

Affected Software

1 affected component
WireGuard Portal (wg-portal)>=2.2.0<2.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade wg-portal to a version that resolves this vulnerability.

    Fixed in 2.3.0

Event History

Sep 17, 2026
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated low-privilege wg-portal user can exploit it. No administrator privileges or user interaction are required.

2

What information can an affected user obtain?

The WebSocket can expose other users' peer public keys and received/transmitted byte counters, as well as interface statistics and interface names. It does not expose tunnel content, AllowedIPs, or user identities.

3

Which deployments are affected?

wg-portal versions from 2.2.0 up to, but not including, 2.3.0 are affected. The issue is fixed in version 2.3.0.

4

How can I determine whether users may already have accessed this data?

Review whether the affected deployment permitted low-privilege authenticated users to connect to GET /api/v0/ws. The provided information does not identify specific logging or audit records that would confirm prior access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203