CVE-2026-26899

An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-27 17:17

Updated : 2026-09-01 20:17


NVD link : CVE-2026-26899

Mitre link : CVE-2026-26899

CVE.ORG link : CVE-2026-26899


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')