CVE-2026-15732 Details
Description
A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.
A Server-Side Request Forgery (SSRF) vulnerability exists in WGDashboard versions through 4.2.3. This vulnerability allows authenticated attackers to make arbitrary HTTP requests via the webhook functionality, without any validation of the URL. The full response from these requests is stored in the database and can be retrieved through the API.
Users are advised to update to WGDashboard version 4.3.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Stuub/WGDashboard-v4.3.2-Full-Read-SSRF-via-Webhooks-PoC | CISA-ADP | ExploitTechnical Description |
| https://github.com/Stuub/WGDashboard-v4.3.2-Full-Read-SSRF-via-Webhooks-PoC | [email protected] | ExploitTechnical Description |
| https://github.com/WGDashboard/WGDashboard | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| WGDashboard | <= 4.2.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion