CVE-2026-30403 Details
Description
There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can be used to read any file on the victim's server.
An arbitrary file read vulnerability has been identified in the wgcloud application, specifically in versions through 3.6.2. This vulnerability resides in the backend database management's test connection function, where it can be exploited to read any file from the victim's server. The issue is related to how the JDBC URL is handled, particularly with MySQL Connector/J.
Users can update to wgcloud version 3.6.3, but it is unclear if this version fully addresses the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/tianshiyeben/wgcloud/issues/97 | [email protected] | Issue Tracking |
| https://github.com/TTTlw1024/qwe/issues/2 | [email protected] | ExploitIssue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| wgstart wgcloud | <= 3.6.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2026 | Initial Analysis | [email protected] |
| Mar 24, 2026 | CVE Modified | CISA-ADP |
| Mar 19, 2026 | New CVE Received | [email protected] |