PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-55159 openwrt CVE debrief

CVE-2026-55159 is a high-severity vulnerability in the luci-app-adblock-fast WebUI for OpenWrt, which allows an authenticated delegated user with the write ACL to create a persistent command execution as UID 0 when cron runs. The issue is fixed in version 1.2.4-2. This vulnerability impacts OpenWrt systems with luci-app-adblock-fast installed, allowing attackers to execute commands with elevated privileges. Defenders should assess exposure and prioritize verification and remediation to mitigate potential impact.

Vendor
openwrt
Product
luci-app-adblock-fast
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-21
Original CVE updated
2026-09-29
Advisory published
2026-09-21
Advisory updated
2026-09-29

Who should care

Defenders responsible for OpenWrt systems with luci-app-adblock-fast installed should assess exposure and prioritize verification and remediation. This includes reviewing affected versions, verifying exposure, and updating to version 1.2.4-2. Additionally, defenders should restrict access to the luci-app-adblock-fast write ACL and monitor cron entries for suspicious activity to mitigate potential impact.

Why it matters

CVE-2026-55159 is a high-severity vulnerability in luci-app-adblock-fast for OpenWrt, allowing authenticated delegated users with the write ACL to create a persistent command execution as UID 0. Defenders should prioritize verification, updating, and monitoring to mitigate potential impact.

  • Persistent command execution as UID 0 when cron runs
  • Potential for unauthorized access and command execution
  • Need for verification of affected versions and exposure
  • Priority for updating to version 1.2.4-2

Technical summary

The luci-app-adblock-fast WebUI for OpenWrt is vulnerable to a command execution issue when an authenticated delegated user with the write ACL creates a cron entry with carriage-return or line-feed characters. The issue is fixed in version 1.2.4-2. This vulnerability allows attackers to execute commands with elevated privileges, impacting OpenWrt systems with luci-app-adblock-fast installed. Defenders should prioritize verifying and updating to version 1.2.4-2, restricting access to the luci-app-adblock-fast write ACL, and monitoring cron entries for suspicious activity.

Defensive priority

Defenders should prioritize verifying and updating to version 1.2.4-2, restricting access to the luci-app-adblock-fast write ACL, and monitoring cron entries for suspicious activity.

Recommended defensive actions

  • Verify and update to version 1.2.4-2
  • Restrict access to the luci-app-adblock-fast write ACL
  • Monitor cron entries for suspicious activity
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, its impact, and the fixed version. However, the scope of affected versions and potential exploitation require further verification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-55159 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-55159

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-55159 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55159

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.