CVE-2020-13866: Qbik Wingate

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

Affected products

  • Qbik Wingate: version 9.4.1.5998 only

Published 2020-06-08. Last modified 2026-06-17.