CVE-2026-26899 | OpenWrt luci-app-https-dns-proxy prior 2026-01-17 luci.https-dns-proxy setInitAction Name os command injection
A vulnerability identified as very critical has been detected in OpenWrt luci-app-https-dns-proxy. Impacted is the function setInitAction of the file /usr/libexec/rpcd/luci.https-dns-proxy. This manipulation of the argument Name causes os command injection.
This vulnerability is handled as CVE-2026-26899. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More