ACL Inconsistency in luci-app-lxc Affects OpenWrt Users
CVE-2026-72842

9.4CRITICAL

Key Information:

Vendor

Openwrt

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-72842?

The luci-app-lxc component in OpenWrt is vulnerable to an ACL inconsistency, allowing low-privileged authenticated users to access backend container management routes without sufficient authorization checks. This vulnerability can be exploited via path traversal techniques in the lxc_name parameter, enabling attackers to navigate outside of intended directories and execute host-side scripts with elevated privileges. As a result, this can lead to unauthorized control over the OpenWrt host, compromising system integrity and security.

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

faller-dql
.