๐Ÿ” CVE Alert

CVE-2026-55159

HIGH 8.8

luci-app-adblock-fast: Delegated `luci-app-adblock-fast` users can reach root command execution by injecting newline-separated cron entries

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as though it were one logical line. An authenticated delegated user with the luci-app-adblock-fast write ACL can therefore create an additional physical root cron entry through applications/luci-app-adblock-fast/root/usr/share/rpcd/ucode/luci.adblock-fast, resulting in persistent command execution as UID 0 when cron runs. The issue is not demonstrated for unauthenticated callers or users without the component write ACL. This vulnerability is fixed in 1.2.4-2.

CWE CWE-93
Vendor openwrt
Product luci-app-adblock-fast
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for openwrt luci-app-adblock-fast

Be the first to know when new high vulnerabilities affecting openwrt luci-app-adblock-fast are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

openwrt / luci-app-adblock-fast
< 1.2.4-2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openwrt/luci/security/advisories/GHSA-ggpf-xrph-wg5v github.com: https://github.com/openwrt/luci/pull/8705 github.com: https://github.com/openwrt/luci/commit/9ccd99b5898457e5ef39dc21aea226d7fb6e5c7e github.com: https://github.com/openwrt/luci/commit/f67461fd0255bf992b2b559c22ec288067f2f9da