GNU wget Windows Builds 1.21.4 use_askpass leads to LPE
CVE-2026-94574 Published on September 22, 2026
CVE-2026-94574
A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execution via the use_askpass directive, potentially allowing local privilege escalation.
Vulnerability Analysis
CVE-2026-94574 is exploitable with local system access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Products Associated with CVE-2026-94574
Want to know whenever a new CVE is published for GNU Wget? stack.watch will email you.
Affected Versions
GNU Wget (Windows Builds) Wget:- Before and including 1.21.4 is affected.