ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path by placing malicious executables in specific file system locations to gain elevated privileges during service startup.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Protonvpn
Protonvpn protonvpn |
|
| Vendors & Products |
Protonvpn
Protonvpn protonvpn |
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path by placing malicious executables in specific file system locations to gain elevated privileges during service startup. | |
| Title | ProtonVPN 1.26.0 - Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-01-13T22:51:53.350Z
Updated: 2026-01-14T15:47:13.635Z
Reserved: 2026-01-11T13:14:18.877Z
Link: CVE-2022-50917
Updated: 2026-01-14T15:47:10.875Z
Status : Awaiting Analysis
Published: 2026-01-13T23:15:55.250
Modified: 2026-01-14T16:25:12.057
Link: CVE-2022-50917
No data.