ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path by placing malicious executables in specific file system locations to gain elevated privileges during service startup.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path by placing malicious executables in specific file system locations to gain elevated privileges during service startup. | |
| Title | ProtonVPN 1.26.0 - Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-13T22:51:53.350Z
Reserved: 2026-01-11T13:14:18.877Z
Link: CVE-2022-50917
No data.
Status : Received
Published: 2026-01-13T23:15:55.250
Modified: 2026-01-13T23:15:55.250
Link: CVE-2022-50917
No data.
OpenCVE Enrichment
No data.