Unknown · Wireguard Portal · CVE-2026-54551
**Name of the Vulnerable Software and Affected Versions**
WireGuard Portal versions 2.2.0 through 2.2.x
**Description**
An authorization flaw exists in the authenticated GET '/api/v0/ws' statistics WebSocket within the `handleWebsocket()` function. The system subscribes to `TopicPeerStatsUpdated` and `TopicInterfaceStatsUpdated` and forwards `TrafficDelta` events without verifying per-user authorization. This allows a low-privilege user to enumerate peer public keys via `EntityId` and monitor `BytesReceived` and `BytesTransmitted` values for peers belonging to other users. Additionally, the connection exposes `interface stats` and interface names, which are typically restricted to administrators in the REST API.
**Recommendations**
Update to version 2.3.0.