{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/luci-app-lxc/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-72842"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["luci-app-lxc"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenWrt"],"content_html":"\u003cp\u003eThe OpenWrt luci-app-lxc package contains a critical ACL inconsistency vulnerability that permits authenticated, low-privileged users to bypass authorization controls. This flaw specifically affects backend container management routes. By exploiting a path traversal vulnerability triggered via the \u003ccode\u003elxc_name\u003c/code\u003e parameter, an attacker can escape the intended container isolation boundaries.\u003c/p\u003e\n\u003cp\u003eThe exploit utilizes the \u003ccode\u003e/.%2E\u003c/code\u003e sequence to traverse directories and gain access to host-level configurations. Once access is achieved, an attacker can manipulate host-side scripts, specifically those defined in \u003ccode\u003elxc.hook.start-host\u003c/code\u003e. Successful exploitation results in arbitrary code execution with root privileges on the underlying OpenWrt host. This vulnerability has been assigned a CVSS v3.1 base score of 9.9, highlighting the severe risk to network infrastructure running affected OpenWrt firmware versions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the LuCI web interface with low-privileged credentials.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious request targeting backend container management routes.\u003c/li\u003e\n\u003cli\u003eAttacker injects a path traversal payload \u003ccode\u003e/.%2E\u003c/code\u003e into the \u003ccode\u003elxc_name\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe application fails to validate the input, allowing the attacker to escape the container directory structure.\u003c/li\u003e\n\u003cli\u003eAttacker locates the \u003ccode\u003elxc.hook.start-host\u003c/code\u003e configuration file on the host filesystem.\u003c/li\u003e\n\u003cli\u003eAttacker overwrites or modifies the hook script to include arbitrary malicious commands.\u003c/li\u003e\n\u003cli\u003eThe system triggers the hook script during a container start event.\u003c/li\u003e\n\u003cli\u003eThe host executes the attacker-controlled script with root privileges, resulting in full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability grants an attacker full root access to the OpenWrt host, which typically serves as the edge gateway or router. An attacker could intercept network traffic, modify firewall rules, establish persistent backdoor access, or use the device as a pivot point into the internal network. Given the typical placement of OpenWrt devices at the network perimeter, this represents a significant risk to the entire organizational infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate OpenWrt firmware to the latest version, ensuring the \u003ccode\u003eluci-app-lxc\u003c/code\u003e package is patched to the version addressing CVE-2026-72842.\u003c/li\u003e\n\u003cli\u003eRestrict access to the LuCI web management interface to trusted internal management subnets via the host firewall (e.g., iptables or nftables rules).\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized access attempts to the container management backend routes.\u003c/li\u003e\n\u003cli\u003eDisable the \u003ccode\u003eluci-app-lxc\u003c/code\u003e package if container management is not required on the device.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T00:05:57Z","date_published":"2026-08-14T00:05:57Z","id":"https://feed.craftedsignal.io/briefs/2026-08-luci-lxc-acl/","summary":"An ACL inconsistency in the OpenWrt luci-app-lxc package allows authenticated low-privileged users to achieve root code execution via path traversal and hook script manipulation.","title":"Authorization Bypass and RCE in luci-app-lxc","url":"https://feed.craftedsignal.io/briefs/2026-08-luci-lxc-acl/"}],"language":"en","title":"CraftedSignal Threat Feed - Luci-App-Lxc","version":"https://jsonfeed.org/version/1.1"}