PT-2026-71904 · Openwrt · Luci-App-Openvpn

·

CVE-2026-72841

·

Published

2026-08-13

·

Updated

2026-08-18

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions luci-app-openvpn (affected versions not specified)
Description Authenticated users can perform path traversal and write arbitrary files outside the intended directory because the software fails to properly validate the instance name2 parameter during file upload. This allows attackers to upload malicious payloads, such as SSH keys, into system directories to achieve persistent root code execution upon reboot.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72841

Affected Products

Luci-App-Openvpn