CVE-2026-72840: Openwrt Luci
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default busybox crond daemon executes as root within one minute.
Affected products
- Openwrt Luci: up to and including 24.10.8; from 25.12.0, up to and including 25.12.5
Published 2026-08-13. Last modified 2026-09-30.