SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-61876

HIGH · CVSS 8.8 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-12 · Last synced 2026-08-11

CyberRota Analysis

AI-Generated

LuCI versions are vulnerable due to improper encoding of DHCPv6 lease hostnames, enabling adjacent network attackers to inject malicious HTML markup. This flaw allows attackers to execute scripts in the administrator's browser when they view DHCP lease pages, potentially leading to unauthorized actions or data exposure. Network administrators and organizations using LuCI should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61876
Severity
HIGH
CVSS
8.8
EPSS
0.20%

Original NVD Description

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages.