Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-72841: OpenVPN Configuration File Upload Allows Unauthorized Code Execution
CVE-2026-72841 · published 21 days ago
Summary
Authenticated users can upload malicious files to gain root access. This happens because the system doesn't properly check where uploaded files are saved. To fix this, administrators should update the OpenVPN configuration to ensure secure file uploads and consider restricting access to sensitive directories.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| openwrt | luci | All versions |
Original advisory text
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended di...
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code execution by placing SSH keys in system directories accessible on reboot.
Severity
9.4
Critical
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 9.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-73External Control of File Name or Path
Timeline
Published13 Aug 2026
Updated3 Sep 2026
First seen13 Aug 2026
Monitor software like this
Free during beta