CVE-2026-72840: Openwrt Luci

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default busybox crond daemon executes as root within one minute.

Affected products

  • Openwrt Luci: up to and including 24.10.8; from 25.12.0, up to and including 25.12.5

Published 2026-08-13. Last modified 2026-09-30.