CVE-2026-72842

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control host-side scripts executed through `lxc.hook.start-host`, achieving root code execution on the OpenWrt host.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-13 22:17

Updated : 2026-09-09 20:35


NVD link : CVE-2026-72842

Mitre link : CVE-2026-72842

CVE.ORG link : CVE-2026-72842


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path