CVE-2026-69095

Source
https://cve.org/CVERecord?id=CVE-2026-69095
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-69095.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-69095
Aliases
  • GHSA-8qcq-jgrj-gvmj
Published
2026-08-03T13:20:47Z
Modified
2026-10-08T02:51:38Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenWrt luci-app-bmx7 Path Traversal via bmx7-info
Details

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the intended directory and read sensitive files accessible to the CGI process.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69095.json"
}
References

Affected packages

Git / github.com/openwrt/luci

Affected ranges

Type
GIT
Repo
https://github.com/openwrt/luci
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-69095.json"