Progress SoftwareCVE-2026-65938
Progress Software WhatsUp Gold: improper authorization
Medium4.3CVE-2026-65938 · Published Aug 12, 2026 · updated Sep 2, 2026
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| WhatsUp Gold Product | < 26.0.2 | 26.0.2 |
Details and references
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Progress Software ShareFile Storage Zones Controller: remote code execution | High7.2 | No fix yet |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: unsafe deserialization | High8.0 | No fix yet |
| Aug 12 | Progress Software WhatsUp Gold: remote code execution | High8.8 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: cross-site scripting | High8.0 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: path traversal | Medium6.8 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: insecure default permissions | Medium6.8 | 26.0.2 |