OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-55159

HIGH · CVSS 8.8 EPSS 0.49% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The luci-app-adblock-fast WebUI for OpenWrt is vulnerable due to improper handling of carriage-return or line-feed characters in the luci.adblock-fast.setCronEntry RPC method, allowing authenticated users with write access to create unauthorized cron entries. This could lead to persistent command execution with root privileges, posing a significant security risk. Organizations using this application, especially those with delegated user access, should prioritize upgrading to version 1.2.4-2 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55159
Severity
HIGH
CVSS
8.8
EPSS
0.49%

Original NVD Description

luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as though it were one logical line. An authenticated delegated user with the luci-app-adblock-fast write ACL can therefore create an additional physical root cron entry through applications/luci-app-adblock-fast/root/usr/share/rpcd/ucode/luci.adblock-fast, resulting in persistent command execution as UID 0 when cron runs. The issue is not demonstrated for unauthenticated callers or users without the component write ACL. This vulnerability is fixed in 1.2.4-2.