CVE-2026-53605

Source
https://cve.org/CVERecord?id=CVE-2026-53605
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53605.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53605
Aliases
  • GHSA-7rhg-9v48-x3h2
Published
2026-09-30T17:09:23Z
Modified
2026-10-02T03:47:27Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl Grant
Details

Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-250",
        "CWE-269"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53605.json"
}
References

Affected packages

Git / github.com/pollen-robotics/reachy-mini-os

Affected ranges

Type
GIT
Repo
https://github.com/pollen-robotics/reachy-mini-os
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.2.4"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.0.10
v0.0.11
v0.0.12
v0.0.3
v0.0.5
v0.0.8
v0.1.0
v0.2.0
v0.2.1
v0.2.2
v0.2.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53605.json"