Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-26899

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 OpenWrt 的 luci-app-https-dns-proxy 中发现了问题(OpenWrt 拉取请求 #15,2026-01-17 之前)。位于 /usr/libexec/rpcd/luci.https-dns-proxy 中的 setInitAction 函数允许经过身份验证的用户通过 name 参数中的 shell 元字符执行任意 shell 命令。

AI Predicted 8.1 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-26899

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-26899

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-26899

登录查看更多情报信息。

Patches & Fixes for CVE-2026-26899 (1)

Exploits & Public PoCs for CVE-2026-26899 (1)

Same Patch Batch · n/a · 2026-08-27 · 28 CVEs total

CVE-2026-30051 free5gc 4.1.0 CreateUEContextProcedure DoS
CVE-2026-30070 free5gc v4.0.1 HandleGetSharedData拒绝服务漏洞
CVE-2026-30069 free5gc v4.0.1 UDMC空指针解引用致DoS
CVE-2026-30057 free5gc v4.1.0 拒绝服务漏洞
CVE-2026-30050 free5gc v4.1.0 ModifyAMFEventSubscriptionProcedure DoS
CVE-2026-30056 free5gc v4.0.1空指针引用致拒绝服务
CVE-2026-30072 free5gc v4.0.1空指针解引用致拒绝服务
CVE-2026-30060 free5gc v4.0.1 SUCI解析致DoS漏洞
CVE-2026-30046 Open5GS v2.7.6 NUDM-UECM断言拒绝服务
CVE-2026-30068 free5gc v4.0.1输入验证缺陷致DoS
CVE-2026-30058 free5gc 4.0.1 HTTPModifySubscription DoS漏洞
CVE-2026-30059 free5gc v4.0.1 NAS解码器拒绝服务漏洞
CVE-2026-30063 free5gc v4.0.1 NF发现端点DoS漏洞
CVE-2026-30067 free5gc 4.0.1 NRF DoS漏洞
CVE-2026-75357 B站桌面端1.17.9远程代码执行漏洞
CVE-2026-30045 open5gs v2.7.6 NF-INSTANCES整数溢出致DoS
CVE-2026-30073 free5gc v4.0.1 DoS漏洞
CVE-2026-30071 free5gc 4.0.1 RechargePut函数拒绝服务漏洞
CVE-2026-30062 free5gc v4.0.1 NGAP处理器拒绝服务漏洞
CVE-2026-30064 free5gc v4.0.1 buildFilter输入验证不当导致拒绝服务

Showing top 20 of 28 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-26899

No comments yet


Leave a comment