CVE-2026-30404

The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulnerability. This issue can be exploited to make the server send requests to probe the internal network, remotely download malicious files, and perform other dangerous operations.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:wgstart:wgcloud:*:*:*:*:*:*:*:*

History

02 Apr 2026, 12:20

Type Values Removed Values Added
First Time Wgstart wgcloud
Wgstart
CPE cpe:2.3:a:wgstart:wgcloud:*:*:*:*:*:*:*:*
References () https://github.com/TTTlw1024/qwe/issues/3 - () https://github.com/TTTlw1024/qwe/issues/3 - Exploit, Issue Tracking
References () https://github.com/tianshiyeben/wgcloud/issues/98 - () https://github.com/tianshiyeben/wgcloud/issues/98 - Issue Tracking

24 Mar 2026, 02:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-918
Summary
  • (es) La característica de prueba de conexión de gestión de base de datos de backend en wgcloud v3.6.3 tiene una vulnerabilidad de falsificación de petición del lado del servidor (SSRF). Este problema puede ser explotado para hacer que el servidor envíe peticiones para sondear la red interna, descargar archivos maliciosos de forma remota y realizar otras operaciones peligrosas.

19 Mar 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 16:16

Updated : 2026-04-02 12:20


NVD link : CVE-2026-30404

Mitre link : CVE-2026-30404

CVE.ORG link : CVE-2026-30404


JSON object : View

Products Affected

wgstart

  • wgcloud
CWE
CWE-918

Server-Side Request Forgery (SSRF)