Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-72842: OpenWrt luci-app-lxc allows unauthorized access to containers

CVE-2026-72842 · published 21 days ago
Summary

A security issue affects OpenWrt's luci-app-lxc, allowing users with limited access to control containers and potentially gain root access on the device. This means that an attacker could gain control over the entire system. To stay secure, update your OpenWrt device to the latest version as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
openwrt luci All versions
Original advisory text
OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control host-side scripts executed through `lxc.hook.start-host`, achieving root code execution on the OpenWrt host.
Severity
9.4 Critical
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 9.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-73External Control of File Name or Path
Timeline
Published13 Aug 2026
Updated3 Sep 2026
First seen13 Aug 2026
Sources
CVE-2026-72842 · MITRE
Monitor software like this
Free during beta