Overly Permissive ACL in OpenWrt LuCI Allows Unauthorized Cron Job Execution
CVE-2026-72840

8.7HIGH

Key Information:

Vendor

Openwrt

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72840?

An ACL misconfiguration in OpenWrt LuCI's luci-mod-system-mounts component exposes the /etc/crontabs/root file to authenticated users with only mount configuration privileges. This flaw permits these users to append arbitrary cron jobs through ubus file.write, which the default busybox crond daemon executes with root privileges within a minute. This vulnerability can potentially lead to unauthorized commands being executed on the system with elevated privileges.

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lujiefsi
.