{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/raspap-webgui--3.5.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:raspap:raspap-webgui:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-101860"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["raspap-webgui (\u003c= 3.5.5)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["RaspAP"],"content_html":"\u003cp\u003eA security vulnerability exists in RaspAP raspap-webgui versions 3.5.5 and earlier. The flaw resides within the PluginInstaller::addSudoers function located in 'src/RaspAP/Plugins/PluginInstaller.php'. The component responsible for sudo configuration management fails to properly sanitize or restrict inputs, allowing an attacker to perform unauthorized manipulations of the sudoers file. This vulnerability is classified as improper privilege management and can be initiated remotely. Publicly available exploit code exists, increasing the risk for internet-exposed instances of the web interface. Because the vendor has not responded to disclosure attempts, no official patch is available to remediate the vulnerability at this time. Defenders should isolate affected web interfaces or implement strict access controls to prevent unauthorized remote exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to gain elevated privileges on the underlying host system. By manipulating the sudoers file, an attacker can grant themselves or other users unrestricted root execution permissions. This impact is significant given that RaspAP is typically used to manage networking hardware, and compromise would provide full control over the router or gateway functionality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestrict network access to the raspap-webgui interface to trusted management subnets using network-level firewalls.\u003c/li\u003e\n\u003cli\u003eMonitor the integrity of the /etc/sudoers file for unauthorized modifications.\u003c/li\u003e\n\u003cli\u003eAudit the raspap-webgui process for unexpected child processes or unusual shell spawns.\u003c/li\u003e\n\u003cli\u003eDisable the web-based sudo configuration component if it is not strictly required for environment operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T02:24:08Z","date_published":"2026-09-29T02:24:08Z","id":"https://feed.craftedsignal.io/briefs/2026-09-raspap-privilege-escalation/","summary":"An improper privilege management vulnerability in RaspAP raspap-webgui allows remote attackers to manipulate sudo configuration files, potentially leading to unauthorized privilege escalation.","title":"Privilege Management Vulnerability in RaspAP raspap-webgui","url":"https://feed.craftedsignal.io/briefs/2026-09-raspap-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Raspap-Webgui (\u003c= 3.5.5)","version":"https://jsonfeed.org/version/1.1"}