PT-2026-96233 · Openwrt · Luci-App-Advanced-Reboot

CVE-2026-55897

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions luci-app-advanced-reboot versions prior to 1.1.2-6
Description An issue exists where the read Access Control List (ACL) in the file applications/luci-app-advanced-reboot/root/usr/share/rpcd/acl.d/luci-app-advanced-reboot.json grants rpcd the file.exec permission for the /bin/sh shell interpreter. An authenticated delegated session with this ACL can provide caller-controlled parameters. Because rpcd authorizes the executable path and passes these arguments to the shell, it allows for the execution of arbitrary commands with root privileges.
Recommendations Update to version 1.1.2-6.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55897
GHSA-VJ96-F37G-37F6

Affected Products

Luci-App-Advanced-Reboot