What is CVE-2026-72842?
An ACL inconsistency vulnerability in luci-app-lxc allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories. Affected users should immediately apply security updates and enforce strict network access controls.
Azərbaycanca: luci-app-lxc komponentində ACL uyğunsuzluğu zəifliyi aşkar edilib. Bu, aşağı səlahiyyətli autentifikasiya olunmuş LuCI istifadəçilərinə müvafiq icazə yoxlaması olmadan backend konteyner idarəetmə marşrutlarına giriş imkanı verir. Xüsusilə, `lxc_name` parametrində `/.%2E` istifadə edilərək path traversal həyata keçirilə bilər ki, bu da konteyner fayl sistemlərinin sərhədlərindən çıxmağa səbəb olur. Təsirə məruz qalan istifadəçilər dərhal təhlükəsizlik yeniləməsini tətbiq etməli və şəbəkə giriş nəzarətini gücləndirməlidirlər.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
How does CVE-2026-72842 affect luci-app-lxc users?
This ACL inconsistency vulnerability allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories.
What measures should be taken to protect against CVE-2026-72842?
Affected users should immediately apply security updates and enforce strict network access controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.