CVE-2026-24788: Raspap Raspap-Webgui
High severity, CVSS 8.7. EPSS: 1.4% chance of exploitation in the next 30 days.
RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.
Affected products
- Raspap Raspap-Webgui: before 3.3.6 (fixed in 3.3.6)
Published 2026-02-02. Last modified 2026-06-17.