SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-68583

MEDIUM · CVSS 5.4 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

Luci-app-adblock-fast versions prior to 1.2.4-4 are vulnerable to a stored cross-site scripting (XSS) attack through the blocklist name field, allowing lower-privileged users to inject malicious HTML. This vulnerability can result in the execution of the injected payload in the administrator's browser when accessing the AdBlock Fast status page, potentially compromising sensitive information or session tokens. Administrators of systems using this application should prioritize updating to the latest version to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-68583
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%

Original NVD Description

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin.