OS Command Injection Vulnerability in OpenWrt luci-app-dockerman
CVE-2026-69096
8.7HIGH
What is CVE-2026-69096?
The luci-app-dockerman package in OpenWrt's recent snapshots exposes an OS command injection vulnerability due to improperly handled user inputs in the HTTP POST requests. The docker.container.ttyd_start method is accessible with broad ubus permissions, allowing authenticated users to inject shell metacharacters into system commands. This flaw can lead to arbitrary command execution as root when exploited, posing significant security risks for systems utilizing this package. Prior versions, such as openwrt-24.10 and openwrt-23.05, are unaffected as they lack the vulnerable backend.
Affected Version(s)
luci 26.162.29621~507ab5e
