Three vulnerabilities in RaspAP raspap-webgui were disclosed on September 28, 2026 — all with public proof-of-concept exploits. The vendor was contacted and did not respond. No patches exist.
The CVEs
| CVE | CVSS | Type | Component |
|---|---|---|---|
| CVE-2026-101860 | 8.8 | Privilege escalation | PluginInstaller::addSudoers |
| CVE-2026-101859 | 5.4 | OS command injection | OpenVPN del_ovpncfg.php |
| CVE-2026-101858 | 4.7 | OS command injection | WiFiManager::writeWpaSupplicant |
What happened
CVE-2026-101860 is the serious one. The PluginInstaller::addSudoers function allows manipulation of the sudoers configuration without adequate authorization checks. An attacker with web interface access can grant themselves unrestricted root execution on the underlying Raspberry Pi OS.
CVE-2026-101859 is OS command injection via the cfg_id parameter in ajax/openvpn/del_ovpncfg.php. The escapeshellcmd function is used incorrectly — injection through the OpenVPN configuration deletion handler.
CVE-2026-101858 is OS command injection via the ssid argument in WiFiManager::writeWpaSupplicant. Requires authenticated access but the barrier is low on a home/edge device.
Why it matters
RaspAP is the de facto standard for turning a Raspberry Pi into a wireless router. These devices sit at the network edge. Root compromise via the web UI = foothold inside your local network.
Public PoCs are available for all three. No vendor fix is coming. The only realistic path is isolation.
What to do right now
- Restrict the web interface — firewall rules, trusted IPs only
- Monitor /etc/sudoers — file integrity monitoring on this path
- Disable plugin installation if you don't use it (removes the CVE-2026-101860 attack surface)
- Strong authentication — change defaults, add 2FA if supported
Full technical analysis with CVSS vectors, CWE classifications, and mitigation checklist:
RaspAP Mass Disclosure — CVE-2026-101860, CVE-2026-101859, CVE-2026-101858
Originally published at ThreatAft
Top comments (0)