SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-72842 2026-08-13

CVE-2026-72842: Critical LuCI Container ACL Flaw Grants Root on OpenWrt

"A critical (CVSS 9.9) ACL inconsistency in OpenWrt's `luci-app-lxc` lets any low-privileged authenticated LuCI user chain a path traversal into root code execution on the host."

A critical (CVSS 9.9) ACL inconsistency in OpenWrt's luci-app-lxc lets any low-privileged authenticated LuCI user chain a path traversal into root code execution on the host.

What Is It

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to reach backend container management routes without proper authorization checks. From there, an attacker can supply a path traversal sequence, /.%2E, in the lxc_name parameter to escape the container directory and control host-side scripts executed via lxc.hook.start-host, achieving root code execution on the OpenWrt host.

The issue is classified as CWE-73 (External Control of File Name or Path). It was disclosed through VulnCheck.

Why It Matters

The severity metrics in the CVE record are CNA-supplied, not NVD-assigned: the record is still in Received status, meaning NVD has not completed its own analysis or published an independent score. As submitted, the record carries a CVSS 3.1 base score of 9.9 (Critical) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, and a CVSS 4.0 score of 9.4 (Critical). Those scores may change once NVD enriches the entry. The relevant properties as scored:

In practical terms, a restricted web-UI account becomes root on the router. The authorization gap plus the traversal primitive means no separate privilege-escalation bug is needed.

What's Vulnerable

The affected vendor and product listed in the record are openwrt / luci, specifically the luci-app-lxc application, with a default status of affected. Consistent with the record's un-enriched Received state, the entry contains no CPE version ranges, so no precise affected-version boundaries are available from the supplied data.

Patch Status

The CVE record was published 2026-08-13 with a status of Received and carries no remediation timeline or required-action data. CVE-2026-72842 does not appear in CISA's Known Exploited Vulnerabilities catalog, so active exploitation is not confirmed and no KEV due date applies. The upstream GitHub Security Advisory (GHSA-jf59-v86x-fwf2) is the authoritative source for both fix availability and the vendor's own severity assessment; operators running luci-app-lxc should consult it directly and, in the interim, restrict LuCI account access and exposure of the management interface.

Sources