CVE-2026-101860 | RaspAP raspap-webgui up to 3.5.5 sudo Configuration PluginInstaller.php addSudoers privileges management
A vulnerability marked as critical has been reported in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management.
This vulnerability was named CVE-2026-101860. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More