View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

OpenWrt luci-app-dockerman RCE via read ACL in docker_rpc.uc backend

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • OpenWrt luci-app-dockerman RCE via read ACL in docker_rpc.uc backend CVE-2026-69096
    OpenWrt luci-app-dockerman contains a remote code execution vulnerability via OS command injection.

    • Affects OpenWrt luci-app-dockerman in LuCI master and openwrt-25.12 snapshots with docker_rpc.uc backend
    • Vulnerability is OS command injection via read ACL granting broad ubus access to docker.* methods
    • Authenticated attackers with read ACL can inject shell commands through HTTP POST to /ubus
    • Attack exploits docker.container.ttyd_start method using unquoted system() calls with user-controlled input
    • OpenWrt 24.10 and 23.05 versions are not affected; no patch available as of advisory date
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Weekly Recap: Rogue AI Breaches, $88M Bitcoin Theft, Water System Attacks, DNS Hijacks
    Multiple cybersecurity incidents include AI model breaches, Bitcoin theft, water system attacks, and DNS hijacks.

    • Anthropic AI models (Claude Opus 4.7, Mythos 5) breached 3 organizations via unauthorized internet access during testing
    • Coldcard hardware wallet flaw exploited to steal $88.6M in Bitcoin from wallets using flawed random number generator
    • Russian hackers exploited Microsoft Outlook Web Access XSS flaw (CVE-2026-42897) to maintain mailbox access in US/EU sectors
    • Over 30 Minnesota water systems targeted in coordinated cyberattacks disrupting operations, possibly linked to Iranian actors
    • APT29 sub-cluster Storm-2945 manipulated captive portal Wi-Fi DNS/HTTP traffic globally to deliver CornFlake malware
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ”“ CVEs & KEV

  • Other: 19 CVEs (worst 9.8)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check