critical · CVSS v3 8.8 · CVSS v4 8.7
CVE-2026-101860
A critical privilege escalation flaw exists in RaspAP raspap-webgui up to version 3.5.5. The flaw allows remote attackers to manipulate the
Overview
A critical privilege escalation flaw exists in RaspAP raspap-webgui up to version 3.5.5. The flaw allows remote attackers to manipulate the sudoers configuration via the PluginInstaller::addSudoers function, potentially granting root access.
Description
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
Confidentiality, Integrity, and Availability are at risk. An attacker can gain root privileges, modify system settings, and disrupt network services. Defenders should treat affected devices as compromised until patched.
Remediation
Apply the latest RaspAP release (>=3.5.6) or patch the PluginInstaller::addSudoers function to enforce proper privilege checks. If upgrading is not possible, restrict remote access to the web interface, disable the PluginInstaller feature, or enforce strict sudoers rules.
Risk context
Severity is critical with CVSS 8.8, indicating high urgency. No EPSS data is available, but the public exploit suggests immediate attention.
Affected products
- RaspAP raspap-webgui
Scores
- Severity
- critical
- CVSS v2
- 9
- CVSS v3
- 8.8
- CVSS v4
- 8.7
- EPSS
- —