CVE-2026-24788Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-02: 4Technical Details · 2026-02-02: 302-02
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in RaspAP raspap-webgui (CVE-2026-24788) https://vuldb.com/?id.343681

    Post summary

    A new vulnerability (CVE-2026-24788) affecting RaspAP raspap-webgui has been disclosed with elevated criticality, but no details about exploitation, patches, or PoC are provided.

    0001091
    2.1K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-24788: HIGH] RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.#cve,CVE-2026-24788,#cybersecurity https://cvefind.com/CVE-2026-24788

    Post summary

    This post discloses a high‑severity OS command injection vulnerability in RaspAP raspap-webgui versions prior to 3.3.6 that allows authenticated users to execute arbitrary commands.

    0000097
    583 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24788 OS Command Injection Vulnerability in RaspAP WebGUI Prior to 3.3.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24788

    Post summary

    The post announces CVE-2026-24788, an OS command injection flaw in RaspAP WebGUI before version 3.3.6, without providing PoC, exploit code, or mitigation details.

    00000121
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-24788 - High RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product. https://www.thehackerwire.com/vulnerability/CVE-2026-24788/ https://t.co/i8XmkECGoU

    Post summary

    CVE-2026-24788 is an OS command injection vulnerability in RaspAP raspap-webgui versions prior to 3.3.6 that allows authenticated users to execute arbitrary OS commands.

    0000059
    113 followersView on X

Explore more