CVE-2026-24788: Raspap Raspap-Webgui

High severity, CVSS 8.7. EPSS: 1.4% chance of exploitation in the next 30 days.

RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.

Affected products

  • Raspap Raspap-Webgui: before 3.3.6 (fixed in 3.3.6)

Published 2026-02-02. Last modified 2026-06-17.