Local Privilege Escalation in Reachy Mini Wireless Robot by Pollen Robotics
CVE-2026-53605
7.8HIGH
What is CVE-2026-53605?
The Reachy Mini Wireless OS for Pollen Robotics' Reachy Mini robot contains a significant local privilege escalation vulnerability. Prior to version 0.2.4, the OS image allowed the 'pollen' daemon user to execute any command via 'systemctl' without requiring a password due to an overly permissive sudoers configuration. This misconfiguration enables any process running as the pollen user to elevate privileges to root with minimal commands and no need for user interaction. The issue has been addressed in version 0.2.4, which restricts the sudo permissions appropriately.
Affected Version(s)
reachy-mini-os < 0.2.4
