ACL Inconsistency in luci-app-lxc Affects OpenWrt Users
CVE-2026-72842
9.4CRITICAL
What is CVE-2026-72842?
The luci-app-lxc component in OpenWrt is vulnerable to an ACL inconsistency, allowing low-privileged authenticated users to access backend container management routes without sufficient authorization checks. This vulnerability can be exploited via path traversal techniques in the lxc_name parameter, enabling attackers to navigate outside of intended directories and execute host-side scripts with elevated privileges. As a result, this can lead to unauthorized control over the OpenWrt host, compromising system integrity and security.
