CVE-2026-24793 is a critical out-of-bounds write vulnerability (classic buffer overflow) affecting AzerothCore WotLK versions up to and including v4.0.0, specifically within the zlib modules (inflate.C). With a CVSS score of 9.8 (Critical), this vulnerability allows for unauthenticated, network-based attacks with high impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) or active exploitation has been observed, and community discussion is minimal, the severe nature of the flaw warrants immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.0.0CPE matchmatch criteria | cpe:2.3:a:azerothcore:azerothcore:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:L/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.