CVE-2026-59260: Openwrt Luci

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command execution when SMB protocol messages are processed.

Affected products

  • Openwrt Luci: before 24.10.8 (fixed in 24.10.8); from 25.12.0, before 25.12.5 (fixed in 25.12.5)

Published 2026-07-12. Last modified 2026-09-30.