Vulnerability Description
OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default busybox crond daemon executes as root within one minute.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/openwrt/luci/security/advisories/GHSA-v5f9-62c7-cw29
- https://www.vulncheck.com/advisories/openwrt-luci-luci-mod-system-mounts-acl-roo
- https://github.com/openwrt/luci/security/advisories/GHSA-v5f9-62c7-cw29
FAQ
What is CVE-2026-72840?
CVE-2026-72840 is a vulnerability with a CVSS score of 8.8 (HIGH). OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users w...
How severe is CVE-2026-72840?
CVE-2026-72840 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72840?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.