rootpwn

critical · CVSS v3 8.8 · CVSS v4 8.7

CVE-2026-101860

A critical privilege escalation flaw exists in RaspAP raspap-webgui up to version 3.5.5. The flaw allows remote attackers to manipulate the

Overview

A critical privilege escalation flaw exists in RaspAP raspap-webgui up to version 3.5.5. The flaw allows remote attackers to manipulate the sudoers configuration via the PluginInstaller::addSudoers function, potentially granting root access.

Description

A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

Confidentiality, Integrity, and Availability are at risk. An attacker can gain root privileges, modify system settings, and disrupt network services. Defenders should treat affected devices as compromised until patched.

Remediation

Apply the latest RaspAP release (>=3.5.6) or patch the PluginInstaller::addSudoers function to enforce proper privilege checks. If upgrading is not possible, restrict remote access to the web interface, disable the PluginInstaller feature, or enforce strict sudoers rules.

Risk context

Severity is critical with CVSS 8.8, indicating high urgency. No EPSS data is available, but the public exploit suggests immediate attention.

Affected products

  • RaspAP raspap-webgui

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
8.7
EPSS
—

privilege-escalation raspberry-pi web-application sudoers critical remote-exploit

← All CVEs