A high-severity vulnerability tracked as CVE-2026-69096 allows authenticated attackers to achieve remote code execution as root in OpenWrt deployments using LuCI master or OpenWrt 25.12 snapshots that include the ucode docker_rpc.uc backend for luci-app-dockerman. The issue combines overly broad read ACL permissions with unsafe command construction in the docker.container.ttyd_start path, where attacker-controlled id, cmd, and uid fields are passed to system() without proper quoting or argv-style handling, enabling OS command injection via an HTTP POST request to /ubus.
The vulnerable code runs in the rpcd root context, meaning a user with only the luci-app-dockerman read ACL can execute arbitrary shell commands with full privileges by injecting shell metacharacters. The flaw is classified as CWE-78 and carries a CVSS v3.1 score vector of AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Advisories state that OpenWrt 24.10 and 23.05 are not affected because they do not include the vulnerable backend, and no patched version was available at the time of disclosure.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE entry states that disclosure@vulncheck.com received the new CVE-2026-69096 on August 3, 2026. The issue concerns an authenticated OS command injection flaw in OpenWrt's luci-app-dockerman component.
VulnCheck published an advisory describing an authenticated OS command injection vulnerability in OpenWrt LuCI master and openwrt-25.12 snapshots with the ucode docker_rpc.uc backend. The advisory said attackers with only the luci-app-dockerman read ACL could send an HTTP POST to /ubus and execute arbitrary commands as root, and noted no patched version was known at the time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.