What is CVE-2026-68583?
CVE-2026-68583 is a stored cross-site scripting vulnerability in luci-app-adblock-fast before version 1.2.4-4 found in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser. Users should immediately update luci-app-adblock-fast to the latest version.
Azərbaycanca: CVE-2026-68583 — luci-app-adblock-fast 1.2.4-4 versiyasından əvvəlki versiyalarda aşkarlanmış stored cross-site scripting zəifliyidir. Bu boşluq blocklist ad sahəsində aktiv HTML inyeksiyasına imkan verir, beləliklə aşağı səlahiyyətli istifadəçi yüklədiyi kod administratorun brauzerində icra oluna bilir. İstifadəçilər luci-app-adblock-fast paketini dərhal ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which software was the CVE-2026-68583 vulnerability discovered?
CVE-2026-68583 is a stored cross-site scripting vulnerability found in luci-app-adblock-fast before version 1.2.4-4.
How is CVE-2026-68583 exploited?
The vulnerability allows active HTML injection in the blocklist name field, so the payload injected by a lower-privileged user executes in the administrator's browser when the administrator views the AdBlock Fast status page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.