
CVE-2026-72842: ACL inconsistency in OpenWrt luci-app-lxc lets any authenticated LuCI user reach admin-only container routes. Path traversal in lxc_name plus lxc.hook.start-host turns it into root code execution on the host. OpenWrt powers millions of routers, so this is a backdoor into edge networks. Tighten LuCI access until luci-app-lxc is patched. https://hol.org/blog/cve-2026-72842-openwrt-luci-app-lxc-acl-bypass
Post summary
The post details an ACL flaw in OpenWrt luci-app-lxc that could allow root execution, advises tightening LuCI access while awaiting a patch, and links to a blog for further information.
