Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-58000: OpenVPN Configuration in LuCI Allows Root Access
CVE-2026-58000
CVE-2026-58000
Summary
A security flaw in LuCI's OpenVPN configuration tool allows an authenticated user to gain root access on a system. This is a serious risk because it lets someone with permission to set up OpenVPN connections take control of the entire system. To fix this, update the LuCI package to the latest version, which should be safe from this vulnerability.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| openwrt | luci-proto-openvpn | <= 0.11.1 |
Original title
luci-proto-openvpn - Command Injection via cl_meta Parameter in generateKey
Original description
luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN protocol configuration access can inject arbitrary shell metacharacters into cl_meta to execute commands as root via the popen function.
nvd CVSS3.1
8.8
nvd CVSS4.0
8.7
Vulnerability type
CWE-78
OS Command Injection
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 29 Jun 2026