Sceawere

Vulnerability Detail

CVE-2026-101860UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RaspAP Improper Privilege Management Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
5h ago
Vendor
RaspAP
Product
raspap-webgui
Attack Type
Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-29T02:16:54.787Z",
  "pubdate": "2026-09-29T02:16:54.787Z",
  "executiveSummary": "A critical improper privilege management vulnerability exists in the RaspAP raspap-webgui component up to version 3.5.5. The vulnerability, located within the PluginInstaller::addSudoers function, allows an attacker to manipulate the sudo configuration of the host system. This flaw facilitates unauthorized privilege escalation, enabling remote attackers to execute arbitrary commands with root privileges. Given that the exploit code has been publicly disclosed and the vendor has remained unresponsive, the risk of exploitation is significantly elevated. Successful exploitation requires the ability to interact with the web GUI but allows a remote actor to gain full system control, compromising the integrity, availability, and confidentiality of the RaspAP installation. Organizations utilizing affected versions are at high risk of total system compromise.",
  "technicalDetails": "The vulnerability originates from insecure handling of sudoers configuration files within the PluginInstaller::addSudoers method in src/RaspAP/Plugins/PluginInstaller.php. This function is designed to facilitate the installation of plugins by updating system-level sudo permissions; however, it fails to implement sufficient input validation or sanitization when appending configuration directives to the /etc/sudoers file or associated include directories. By providing malformed input or injecting malicious directives during the plugin installation process, an attacker can manipulate the system's security policy.\nThe attack flow initiates via the web-based management interface. An attacker exploits the improper privilege management by crafting a malicious payload intended for the PluginInstaller component. Because the application logic does not properly enforce boundaries on the configuration parameters passed to the addSudoers function, the malicious input is written directly into the system's sudoers configuration. This effectively grants the web server process, or a specifically targeted user account controlled by the attacker, unrestricted passwordless sudo access.\nThe exploitation process typically follows these steps: First, the attacker triggers the vulnerable PluginInstaller functionality, often by simulating an authorized plugin installation sequence. Second, they supply input containing command injection sequences that the backend fails to sanitize. Third, the addSudoers function executes, appending the attacker-supplied, malicious lines to the sudoers configuration. Finally, once the configuration is updated, the attacker triggers the execution of system commands through the web interface, which now benefit from escalated root privileges due to the modified sudo policy. This post-exploitation impact allows for complete system compromise, including the installation of persistent backdoors, modification of sensitive configuration files, and exfiltration of system data. The vulnerability is particularly severe because the application architecture inherently places trust in inputs processed by the PluginInstaller class without implementing a secondary validation or integrity check on the resulting sudo configuration file updates. The lack of vendor response means no official patch exists, leaving systems exposed to automated exploitation scripts currently circulating in public repositories."
}
CVE-2026-101860: RaspAP Improper Privilege Management Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere