CVE-2026-65938: WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.
Published Aug 12, 2026
·Updated
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
Affected Software
1 affected component
Ipswitch WhatsUp Gold<26.0.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WhatsUp Goldto a version that resolves this vulnerability.Fixed in 26.0.2
Event History
Aug 12, 2026
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65938?
The severity of CVE-2026-65938 is classified as medium with a score of 4.3.
2
How do I fix CVE-2026-65938?
To fix CVE-2026-65938, upgrade to WhatsUp Gold version 26.0.2 or later.
3
What vulnerability does CVE-2026-65938 exploit?
CVE-2026-65938 exploits an improper authorization vulnerability in the Scheduled Reports API.
4
Who is affected by CVE-2026-65938?
Any user of WhatsUp Gold versions prior to 26.0.2 may be affected by CVE-2026-65938.
5
What actions can be restricted due to CVE-2026-65938?
CVE-2026-65938 allows authenticated users to invoke restricted actions within the Scheduled Reports API.