cvesecurityvulnerability
CVE-2026-49819: UpSnap Initial-Superuser Takeover Chained to Root RCE
UpSnap 4.4.1 through 5.3.5 lets an unauthenticated network-adjacent attacker claim the initial superuser account on a fresh install, then execute shell commands as root through the wake command handler. Upgrade to 5.4.0.