CVE-2026-15732: Wgdashboard

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.

Affected products

Published 2026-08-06. Last modified 2026-09-03.