PatchSiren cyber security CVE debrief
CVE-2026-67352 openwrt CVE debrief
The luci-app-https-dns-proxy package contains a stored cross-site scripting vulnerability in the resolver_url parameter. Authenticated users can inject active HTML, which is rendered as raw HTML and executes JavaScript in the administrator's browser origin when the HTTPS DNS Proxy status page is viewed. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. The CVE record was published on 2026-08-01T13:17:05.860Z and has not been modified since then. This vulnerability affects administrators and users of luci-app-https-dns-proxy, who should be aware of this vulnerability and take necessary actions to mitigate it. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure proper prioritization and remediation efforts. Compensating controls, such as web application firewalls or intrusion detection systems, may be necessary to detect and prevent cross-site scripting attacks while a patch is being developed and deployed. Monitoring for suspicious activity and exception tracking related to the HTTPS DNS Proxy status page is also recommended. Asset inventory and exposure review are crucial to determine if updates are required and to plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are also essential steps in the remediation process.
- Vendor
- openwrt
- Product
- luci
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-01
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-01
Who should care
Administrators and users of luci-app-https-dns-proxy should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure proper prioritization and remediation efforts. Compensating controls, such as web application firewalls or intrusion detection systems, may be necessary to detect and prevent cross-site scripting attacks while a patch is being developed and deployed. Monitoring for suspicious activity and exception tracking related to the HTTPS DNS Proxy status page is also recommended. Asset inventory and exposure review are crucial to determine if updates are required and to plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are also essential steps in the remediation process. The goal is to minimize potential damage and prevent exploitation of the vulnerability. Therefore, it is crucial that the necessary precautions and mitigation strategies are put in place to safeguard against this vulnerability. This may involve collaboration between different teams, including IT, security, and operations, to ensure a comprehensive approach to vulnerability management. By taking proactive steps, organizations can reduce the risk associated with this vulnerability and protect their systems and data from potential attacks. Additionally, it is essential to stay informed about the latest developments and updates related to this vulnerability and to adjust mitigation strategies accordingly. This includes monitoring for new information from the vendor, as well as from other sources, such as security researchers and threat intelligence feeds. By staying informed and taking proactive steps, organizations can minimize the risk associated with this vulnerability and protect their systems and data from potential attacks. The CVE record was published on 2026-08-01T13:17:
Technical summary
The luci-app-https-dns-proxy package contains a stored cross-site scripting vulnerability in the resolver_url parameter. Authenticated users can inject active HTML, which is rendered as raw HTML and executes JavaScript in the administrator's browser origin when the HTTPS DNS Proxy status page is viewed. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. The CVE record was published on 2026-08-01T13:17:05.860Z and has not been modified since then.
Defensive priority
Authenticated users can inject HTML via the resolver_url parameter, allowing JavaScript execution in administrators' browsers when they view the HTTPS DNS Proxy status page.
Recommended defensive actions
- Inventory and assess exposure of luci-app-https-dns-proxy to determine if updates are required.
- Implement compensating controls, such as web application firewalls or intrusion detection systems, to detect and prevent cross-site scripting attacks.
- Monitor for suspicious activity and exception tracking related to the HTTPS DNS Proxy status page.
- Apply vendor remediation when available to patch the vulnerability.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE-2026-67352 record indicates a stored cross-site scripting vulnerability in luci-app-https-dns-proxy's resolver_url parameter. Authenticated users can inject active HTML, which executes JavaScript when administrators view the HTTPS DNS Proxy status page. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. The CVE record was published on 2026-08-01T13:17:05.860Z and has not been modified since then. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:05.860Z and has not been modified since then.