CVE-2026-68583: Openwrt Luci

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin.

Affected products

  • Openwrt Luci: before 1.2.4-4 (fixed in 1.2.4-4)

Published 2026-08-02. Last modified 2026-09-09.