← Back to the live CVE advisory feed

CVE-2026-55897: luci

Severity
8.8 (HIGH)
Vendor
OPENWRT
Affected versions
< 1.1.2-6
Fixed version
1.1.2-6.
Patch status
Patched
Published
2026-09-21T20:17:26.670
Modified
2026-09-21T21:17:05.723

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanced-reboot read ACL in applications/luci-app-advanced-reboot/root/usr/share/rpcd/acl.d/luci-app-advanced-reboot.json grants rpcd file.exec permission for the general shell interpreter /bin/sh. An authenticated delegated session with that read ACL can supply caller-controlled params; rpcd authorizes the executable path and passes those arguments to the shell, allowing arbitrary commands to execute as root. Builds without the /bin/sh exec grant, including the checked openwrt-24.10 and openwrt-23.05 branches, are not affected by this specific chain. This vulnerability is fixed in 1.1.2-6.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 22, 2026 08:00 AM UTC
281 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-77521
MaxKB PATCH
Reporter: SECURITY-ADVISORIES
10
CRITICAL
VIEW RECORD
CVE-2026-79920
ajenti PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-94301
Apache MINA
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-85751
Mailu PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-13355
Meta Box Frontend Submission
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-19658
Give Tributes
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-94571
Product identification pending PATCH
Reporter: CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-94572
Product identification pending PATCH
Reporter: CVE
9.4
CRITICAL
VIEW RECORD
CVE-2026-58491
warpgate PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-94424
MTT S80 Driver Package
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94425
MTT S80 Driver Package
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-94493
PDV5701
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-61674
fluent-bit PATCH
Reporter: SECURITY-ADVISORIES
9.2
CRITICAL
VIEW RECORD
CVE-2025-12999
Eclipse Open VSX
Reporter: EMO
9.1
CRITICAL
VIEW RECORD
CVE-2026-86473
Apache Airflow PATCH
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-46649
joplin PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-79916
MaxKB PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-88807
Product identification pending PATCH
Reporter: MEISSNER
8.9
HIGH
VIEW RECORD
CVE-2026-55563
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.9
HIGH
VIEW RECORD
CVE-2026-92574
Confidential Compute Attestation
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-84285
Product identification pending
Reporter: 3DS.INFORMATION-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-53940
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-82412
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-62371
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-63116
deepstream.io PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-84990
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-62182
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55159
luci-app-adblock-fast PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-55897
luci PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-88409
Product identification pending
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2026-92438
Ninja Forms
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-16651
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65651
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65652
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65653
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-65654
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-89139
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-94381
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.7
HIGH
VIEW RECORD
CVE-2026-94411
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94412
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94496
jshERP
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94497
jshERP
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94501
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-61652
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-94622
vllm
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94623
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94624
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94626
vllm
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94627
vllm
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-94383
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.6
HIGH
VIEW RECORD
CVE-2025-71421
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-94403
iGameCenter
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-55071
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-49811
Product identification pending PATCH
Reporter: SECURITY_ALERT
8.4
HIGH
VIEW RECORD
CVE-2026-94374
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.3
HIGH
VIEW RECORD
CVE-2026-94401
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
8.3
HIGH
VIEW RECORD
CVE-2026-94488
Product identification pending PATCH
Reporter: CVE
8.3
HIGH
VIEW RECORD
CVE-2026-55074
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-61628
nginx-ignition PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-80110
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-94184
Product identification pending
Reporter: SECALERT
8.1
HIGH
VIEW RECORD
CVE-2026-77560
tinyauth PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-83621
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48826
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48975
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-48976
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-62369
kubeedge PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-58269
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-15801
Red Hat OpenShift Container Platform 4
Reporter: SECALERT
8
HIGH
VIEW RECORD
CVE-2026-65980
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.9
HIGH
VIEW RECORD
CVE-2026-55567
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.8
HIGH
VIEW RECORD
CVE-2026-17052
Product identification pending
Reporter: VULNERABILITIES
7.8
HIGH
VIEW RECORD
CVE-2026-49810
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.8
HIGH
VIEW RECORD
CVE-2026-81469
Product identification pending PATCH
Reporter: SECURITY_ALERT
7.8
HIGH
VIEW RECORD
CVE-2026-76898
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-63330
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-55105
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-59814
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-47321
Apache MINA
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91863
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91864
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91865
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-91866
Product identification pending PATCH
Reporter: SECURITY
7.5
HIGH
VIEW RECORD
CVE-2026-88806
Product identification pending PATCH
Reporter: MEISSNER
7.5
HIGH
VIEW RECORD
CVE-2026-52741
gocd PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-61629
nginx-ignition PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-71543
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-94449
Product identification pending
Reporter: SECALERT
7.5
HIGH
VIEW RECORD
CVE-2026-73512
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73513
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73547
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73548
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73550
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73552
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-73553
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-88406
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-88407
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-88411
Product identification pending
Reporter: CVE
7.5
HIGH
VIEW RECORD
CVE-2026-91827
Ninja Forms
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-75939
Product identification pending
Reporter: SECALERT
7.4
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.