A high-severity flaw tracked as CVE-2026-63089 affects WireGuard Easy (wg-easy) through version 15.3.0, allowing unauthenticated attackers to brute-force one-time-link tokens and retrieve sensitive VPN configuration data. The issue stems from token generation based on CRC32 over a random value limited to 0-999, leaving at most 1,000 possible tokens per client ID. Attackers can enumerate those tokens against the unauthenticated /cnf/:oneTimeLink route, which also lacked rate limiting and did not properly enforce token expiration.
Successful exploitation can disclose a peer's PrivateKey and PresharedKey, enabling an attacker to impersonate that WireGuard peer on the VPN network. The project addressed the issue in commit 66b292b11bde3664f05ffb016c8082665d261ded, which added expiration checks for one-time links, tightened authentication behavior, and documented the known brute-force weakness in the one-time-link design, including the limited mitigation provided by short validity windows and one-time use.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A vulnerability affecting WireGuard Easy through version 15.3.0 was disclosed as CVE-2026-63089, describing weak one-time link token generation that leaves at most 1000 candidates per client ID. The flaw allows unauthenticated attackers to brute-force tokens via the /cnf/:oneTimeLink route and recover a peer's PrivateKey and PresharedKey for VPN impersonation.
On June 12, 2026, the wg-easy project committed changes to validate one-time link expiration before use and documented known brute-force weaknesses in the one-time-link design. The commit is identified as the fix for the later-tracked WireGuard Easy token generation vulnerability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.