CVE-2026-30404

HIGH

wgcloud 3.6.3 Database Connection Test - Server-Side Request Forgery

Title source: manual
STIX 2.1

Description

The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulnerability. This issue can be exploited to make the server send requests to probe the internal network, remotely download malicious files, and perform other dangerous operations.

Scores

CVSS v3 7.5
EPSS 0.0025
EPSS Percentile 16.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
wgstart/wgcloud < 3.6.3
Published Mar 19, 2026
Tracked Since Mar 19, 2026