CVE-2026-90441
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 30, 2026
Vendor
unknown
Description
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.