๐Ÿ” CVE Alert

CVE-2026-55897

HIGH 8.8

luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as root

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanced-reboot read ACL in applications/luci-app-advanced-reboot/root/usr/share/rpcd/acl.d/luci-app-advanced-reboot.json grants rpcd file.exec permission for the general shell interpreter /bin/sh. An authenticated delegated session with that read ACL can supply caller-controlled params; rpcd authorizes the executable path and passes those arguments to the shell, allowing arbitrary commands to execute as root. Builds without the /bin/sh exec grant, including the checked openwrt-24.10 and openwrt-23.05 branches, are not affected by this specific chain. This vulnerability is fixed in 1.1.2-6.

CWE CWE-78
Vendor openwrt
Product luci
Published Sep 21, 2026
Last Updated Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for openwrt luci

Be the first to know when new high vulnerabilities affecting openwrt luci are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

openwrt / luci
< 1.1.2-6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openwrt/luci/security/advisories/GHSA-vj96-f37g-37f6 github.com: https://github.com/openwrt/luci/pull/8710 github.com: https://github.com/openwrt/luci/commit/2df00deb122093cbf429266ffef7ad06aaecb48f github.com: https://github.com/openwrt/luci/commit/f85102548ee8325bfd581a0327b210b5f7670829