Openwrt · Luci-App-Openvpn · CVE-2026-72841
**Name of the Vulnerable Software and Affected Versions**
luci-app-openvpn (affected versions not specified)
**Description**
Authenticated users can perform path traversal and write arbitrary files outside the intended directory because the software fails to properly validate the `instance name2` parameter during file upload. This allows attackers to upload malicious payloads, such as SSH keys, into system directories to achieve persistent root code execution upon reboot.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.