๐Ÿ” CVE Alert

CVE-2026-53605

HIGH 7.8

Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl Grant

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.

CWE CWE-250 CWE-269
Vendor pollen-robotics
Product reachy-mini-os
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for pollen-robotics reachy-mini-os

Be the first to know when new high vulnerabilities affecting pollen-robotics reachy-mini-os are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

pollen-robotics / reachy-mini-os
< 0.2.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pollen-robotics/reachy-mini-os/security/advisories/GHSA-7rhg-9v48-x3h2 github.com: https://github.com/pollen-robotics/reachy-mini-os/commit/cee4076f36bd95a2a6b894a56a48c7e971e75445 github.com: https://github.com/pollen-robotics/reachy-mini-os/releases/tag/v0.2.4