Sceawere
Vulnerability Detail
CVE-2026-101860UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
RaspAP Improper Privilege Management Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 5h ago
- Vendor
- RaspAP
- Product
- raspap-webgui
- Attack Type
- Improper Privilege Management
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-29T02:16:54.787Z",
"pubdate": "2026-09-29T02:16:54.787Z",
"executiveSummary": "A critical improper privilege management vulnerability exists in the RaspAP raspap-webgui component up to version 3.5.5. The vulnerability, located within the PluginInstaller::addSudoers function, allows an attacker to manipulate the sudo configuration of the host system. This flaw facilitates unauthorized privilege escalation, enabling remote attackers to execute arbitrary commands with root privileges. Given that the exploit code has been publicly disclosed and the vendor has remained unresponsive, the risk of exploitation is significantly elevated. Successful exploitation requires the ability to interact with the web GUI but allows a remote actor to gain full system control, compromising the integrity, availability, and confidentiality of the RaspAP installation. Organizations utilizing affected versions are at high risk of total system compromise.",
"technicalDetails": "The vulnerability originates from insecure handling of sudoers configuration files within the PluginInstaller::addSudoers method in src/RaspAP/Plugins/PluginInstaller.php. This function is designed to facilitate the installation of plugins by updating system-level sudo permissions; however, it fails to implement sufficient input validation or sanitization when appending configuration directives to the /etc/sudoers file or associated include directories. By providing malformed input or injecting malicious directives during the plugin installation process, an attacker can manipulate the system's security policy.\nThe attack flow initiates via the web-based management interface. An attacker exploits the improper privilege management by crafting a malicious payload intended for the PluginInstaller component. Because the application logic does not properly enforce boundaries on the configuration parameters passed to the addSudoers function, the malicious input is written directly into the system's sudoers configuration. This effectively grants the web server process, or a specifically targeted user account controlled by the attacker, unrestricted passwordless sudo access.\nThe exploitation process typically follows these steps: First, the attacker triggers the vulnerable PluginInstaller functionality, often by simulating an authorized plugin installation sequence. Second, they supply input containing command injection sequences that the backend fails to sanitize. Third, the addSudoers function executes, appending the attacker-supplied, malicious lines to the sudoers configuration. Finally, once the configuration is updated, the attacker triggers the execution of system commands through the web interface, which now benefit from escalated root privileges due to the modified sudo policy. This post-exploitation impact allows for complete system compromise, including the installation of persistent backdoors, modification of sensitive configuration files, and exfiltration of system data. The vulnerability is particularly severe because the application architecture inherently places trust in inputs processed by the PluginInstaller class without implementing a secondary validation or integrity check on the resulting sudo configuration file updates. The lack of vendor response means no official patch exists, leaving systems exposed to automated exploitation scripts currently circulating in public repositories."
}