CVE-2026-65939: WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WhatsUp Goldto a version that resolves this vulnerability.Fixed in 26.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65939?
The severity of CVE-2026-65939 is medium, with a score of 6.8.
What vulnerability does CVE-2026-65939 describe?
CVE-2026-65939 describes an arbitrary file write vulnerability in the LogToFile action handler of WhatsUp Gold versions prior to 26.0.2.
How do I fix CVE-2026-65939?
To fix CVE-2026-65939, upgrade WhatsUp Gold to version 26.0.2 or later.
What can a privileged attacker exploit in CVE-2026-65939?
A privileged attacker can exploit CVE-2026-65939 to create a LogToFile action that allows specifying an arbitrary file extension within the IIS web root.
Which versions of WhatsUp Gold are affected by CVE-2026-65939?
WhatsUp Gold versions prior to 26.0.2 are affected by CVE-2026-65939.