What is CVE-2026-72840?
OpenWrt LuCI contains an overly permissive ACL in luci-mod-system-mounts, granting authenticated users with only mount-configuration privileges write access to /etc/crontabs/root via ubus file.write. This allows low-privileged users to append arbitrary cron entries, potentially leading to remote code execution. Affected users should restrict permissions for the mount-configuration ACL group immediately.
Azərbaycanca: OpenWrt LuCI-də luci-mod-system-mounts modulunda səhv konfiqurasiya olunmuş ACL tərifi, yalnız mount sazlamaq icazəsi olan istifadəçilərə /etc/crontabs/root faylına yazmaq imkanı verir. Bu, autentifikasiya olunmuş aşağı imtiyazlı istifadəçilərin ubus file.write vasitəsilə ixtiyari cron əmrləri əlavə edərək sistemdə özbaşına kod icrasına səbəb ola bilər. LuCI mount-configuration ACL qrupuna malik istifadəçilərin hüquqları dərhal məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which OpenWrt LuCI component is affected by CVE-2026-72840?
This vulnerability is found in the luci-mod-system-mounts module of OpenWrt LuCI.
Which file can be written to via CVE-2026-72840 exploitation?
Users with only mount-configuration privileges can write to /etc/crontabs/root via ubus file.write and append arbitrary cron entries.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.