luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as root (CVE-2026-55897) | HOL Guard CVE