luci-app-lxc contains an ACL inconsistency vulnerability...
Critical severity
Unreviewed
Published
Aug 14, 2026
to the GitHub Advisory Database
•
Updated Aug 14, 2026
Description
Published by the National Vulnerability Database
Aug 13, 2026
Published to the GitHub Advisory Database
Aug 14, 2026
Last updated
Aug 14, 2026
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via
/.%2Ein thelxc_nameparameter to escape container directories and control host-side scripts executed throughlxc.hook.start-host, achieving root code execution on the OpenWrt host.References