CVE-2026-72842Patch

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control host-side scripts executed through `lxc.hook.start-host`, achieving root code execution on the OpenWrt host.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-14: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-14: 108-14
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • HOL@HashgraphOnline
    Patch

    CVE-2026-72842: ACL inconsistency in OpenWrt luci-app-lxc lets any authenticated LuCI user reach admin-only container routes. Path traversal in lxc_name plus lxc.hook.start-host turns it into root code execution on the host. OpenWrt powers millions of routers, so this is a backdoor into edge networks. Tighten LuCI access until luci-app-lxc is patched. https://hol.org/blog/cve-2026-72842-openwrt-luci-app-lxc-acl-bypass

    Post summary

    The post details an ACL flaw in OpenWrt luci-app-lxc that could allow root execution, advises tightening LuCI access while awaiting a patch, and links to a blog for further information.

    020801.8K
    19.2K followersView on X

Explore more