CVE-2026-65940: WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server.
Published Aug 12, 2026
·Updated
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
Affected Software
1 affected component
Ipswitch WhatsUp Gold<26.0.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WhatsUp Goldto a version that resolves this vulnerability.Fixed in 26.0.2
Event History
Aug 12, 2026
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65940?
CVE-2026-65940 has a medium severity rating of 6.8.
2
What vulnerabilities does CVE-2026-65940 present?
CVE-2026-65940 allows a privileged attacker to write arbitrary files to a web-accessible location on the host server.
3
How do I fix CVE-2026-65940?
To fix CVE-2026-65940, upgrade to WhatsUp Gold version 26.0.2 or later.
4
Which versions of WhatsUp Gold are affected by CVE-2026-65940?
WhatsUp Gold versions prior to 26.0.2 are affected by CVE-2026-65940.
5
What type of attack is possible due to CVE-2026-65940?
CVE-2026-65940 enables a privileged attacker to exploit excessive file system permissions.