PT-2026-55199 · Unknown · Travelmate+1

·

CVE-2026-58652

·

Published

2026-07-02

·

Updated

2026-07-02

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions luci-app-travelmate versions 2.4.5-r3 through 2.4.6-1 travelmate versions 2.4.5-r3 through 2.4.6-1
Description A privilege-escalation flaw exists where a LuCI/rpcd session with write ACL for luci-app-travelmate is granted config-wide UCI write access to the travelmate configuration. Although the user interface restricts the auto-login script selection to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service, which runs as root, reads the raw UCI script and script args values and executes the path when the captive-portal auto-login branch f check() in travelmate-functions.sh is reached. An attacker with delegated write permissions can change script to /bin/sh and provide controlled arguments in script args to execute arbitrary commands as root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58652
GHSA-P35R-3323-6G7G

Affected Products

Luci-App-Travelmate
Travelmate