{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-65941",
        "assignerOrgId": "f9fea0b6-671e-4eea-8fde-31911902ae05",
        "state": "PUBLISHED",
        "assignerShortName": "ProgressSoftware",
        "dateReserved": "2026-07-23T16:08:34.531Z",
        "datePublished": "2026-08-12T15:23:54.118Z",
        "dateUpdated": "2026-08-12T16:10:40.937Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "f9fea0b6-671e-4eea-8fde-31911902ae05",
                "shortName": "ProgressSoftware",
                "dateUpdated": "2026-08-12T15:23:54.118Z"
            },
            "title": "WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-306",
                            "description": "CWE-306 Missing authentication for critical function",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-918",
                            "description": "CWE-918 Server-Side Request Forgery (SSRF)",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-73",
                            "description": "CWE-73 External control of file name or path",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-94",
                            "description": "CWE-94 Improper Control of Generation of Code",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-115",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-115 Authentication Bypass"
                        }
                    ]
                },
                {
                    "capecId": "CAPEC-664",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-664 Server Side Request Forgery"
                        }
                    ]
                },
                {
                    "capecId": "CAPEC-650",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-650 Upload a Web Shell to a Web Server"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Progress Software Corporation",
                    "product": "WhatsUp Gold",
                    "platforms": [
                        "Windows"
                    ],
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "26.0.2",
                            "versionType": "semver"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "In WhatsUp Gold versions released before 2026.0.2,&nbsp;<span>an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.</span><br>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.progress.com/network-monitoring"
                },
                {
                    "url": "https://docs.progress.com/bundle/whatsupgold-release-notes-26-0/page/WhatsUp-Gold-2026.0-Release-Notes.html",
                    "tags": [
                        "release-notes"
                    ]
                },
                {
                    "url": "https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2026",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "ADJACENT_NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "HIGH",
                        "baseScore": 8.8,
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Dany Bach from Airbus Security Lab",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.4"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-08-12T16:10:17.382233Z",
                                "id": "CVE-2026-65941",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-08-12T16:10:40.937Z"
                }
            }
        ]
    }
}