{"id":"CVE-2026-94574","title":"A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\\msys64) that is writable by unprivileged users, allowing for arbitrary code execut…","summary":"A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\\msys64) that is writable by unprivileged users, allowing for arbitrary code execut…","severity":"none","cwe":["CWE-427"],"vendor":"GNU Wget (Windows Builds)","product":"Wget","affected":["Wget <= 1.21.4"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:17:13.240","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94574","references":[{"url":"https://atos.net/en/lp/cybershield/a-tale-of-several-hijacks-and-what-it-taught-me-about-runtime-driven-testing","label":"cret@cert.org"},{"url":"https://eternallybored.org/misc/wget/","label":"cret@cert.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-22T20:10:15.102Z","slug":"CVE-2026-94574","body":"## Overview\n\nA local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\\msys64) that is writable by unprivileged users, allowing for arbitrary code execution via the use_askpass directive, potentially allowing local privilege escalation.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}