OS Command Injection Vulnerability in OpenWrt luci-app-dockerman
CVE-2026-69096

8.7HIGH

Key Information:

Vendor

Openwrt

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-69096?

The luci-app-dockerman package in OpenWrt's recent snapshots exposes an OS command injection vulnerability due to improperly handled user inputs in the HTTP POST requests. The docker.container.ttyd_start method is accessible with broad ubus permissions, allowing authenticated users to inject shell metacharacters into system commands. This flaw can lead to arbitrary command execution as root when exploited, posing significant security risks for systems utilizing this package. Prior versions, such as openwrt-24.10 and openwrt-23.05, are unaffected as they lack the vulnerable backend.

Affected Version(s)

luci 26.162.29621~507ab5e

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZwCrazyThursday
.