CVE-2026-15732
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- 0.16%
- 6th pct
- KEV
- No
- Class
- oss containerizable
- CWE-918
Description
A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.
References
Status: profiled · ingested 2026-08-07T18:00:16.000Z