CVE-2026-55159 is a privilege-escalation and command-injection vulnerability in OpenWrt's luci-app-adblock-fast. The flaw allows a logged-in delegated user to achieve root command execution by supplying newline-separated cron entries through the application's configuration path. The vulnerable behavior indicates insufficient neutralization of special elements in data written into cron-managed content, allowing attacker-controlled input to break the intended entry format and introduce additional cron lines that are later executed with root privileges. The issue affects delegated-access scenarios within LuCI where a non-root user is permitted to manage the application but should not be able to execute arbitrary commands as the system superuser.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.