


Perceptive Security
SOC/SIEM Consultancy

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS…
Published:
3 augustus 2026 om 00:00:00
Alert date:
3 augustus 2026 om 17:06:10
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities
A critical OS command injection vulnerability exists in OpenWrt's luci-app-dockerman package, specifically in LuCI master and openwrt-25.12 snapshots that include the ucode docker_rpc.uc RPC backend. The vulnerability stems from the run_ttyd handler building shell commands from user-controlled fields (id, cmd, uid) without proper sanitization or quoting, passing them directly to system() in the rpcd root context. The package's read ACL inadvertently exposes the docker.container.ttyd_start mutating method via broad ubus access grants. An authenticated attacker with only the luci-app-dockerman read ACL can inject shell metacharacters to achieve arbitrary command execution as root via HTTP POST to /ubus. Older versions openwrt-24.10 and openwrt-23.05 are not affected as they lack this backend. No patched version was available at the time of the advisory, though GitHub commits have been referenced as potential fixes.
Technical details
Mitigation steps:
Affected products:
OpenWrt luci-app-dockerman
LuCI master
openwrt-25.12
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69096
https://github.com/openwrt/luci/commit/44618b5b53d9bdad5cd489e82e29688b4d0862c1
https://github.com/openwrt/luci/commit/f4d0a44950e42bcbb8eacf715a3493b276a4f3ac
https://github.com/openwrt/luci/security/advisories/GHSA-cq4h-h8jr-3xqv
https://www.vulncheck.com/advisories/openwrt-luci-app-dockerman-read-acl-remote-code-execution
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
