cvesecurityvulnerability
CVE-2026-72842: OpenWrt luci-app-lxc ACL bypass to root code execution
CVE-2026-72842 lets a low-privileged LuCI user reach admin-only container routes in OpenWrt luci-app-lxc, then chains path traversal in the lxc_name parameter to control lxc.hook.start-host and execute code as root on the host.