CVE-2026-86136
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privil
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 30, 2026 · Last modified: Sep 30, 2026 · CWE-22 · CWE-476 · CWE-862
Not enough EPSS history yet.
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-972855.4 MED—
———Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.4hCVE-2026-972674.3 MED—
———Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.4hCVE-2026-972476.5 MED—
———Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.4hCVE-2026-972435.4 MED—
———Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.4hCVE-2026-972426.8 MED—
———Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.4hCVE-2026-972396.5 MED—
———Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.4h