Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-72842

OpenWrt LuCI Container App ACL Bypass Leads to Root RCE

luci-app-lxc ACL inconsistency lets low-privileged authenticated users exploit path traversal to achieve root code execution on the OpenWrt host. CVSS 9.9 critical.

cat cve-2026-72842.json
Vendor
OpenWrt
Product
LuCI (luci-app-lxc)
CVSS
9.9
EPSS (exploit probability)
0.4%
Status
patched
Published

luci-app-lxc in OpenWrt’s LuCI web interface contains an access control inconsistency. Low-privileged authenticated LuCI users can access backend container management routes without proper authorization checks. The lxc_name parameter is vulnerable to path traversal via /.%2E sequences, allowing an attacker to escape container directories and control host-side scripts executed through lxc.hook.start-host. Those hook scripts run as root on the OpenWrt host.

Affected: OpenWrt installations running luci-app-lxc

Patch: Fix tracked in the upstream OpenWrt LuCI repository. Remove luci-app-lxc if not in use.

Source: GHSA-jf59-v86x-fwf2