CVE-2026-101859
Published 29 September 2026 · tracked since 29 September 2026
Description
A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argument cfg_id leads to os command injection. The attac
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-102264 LOW 3.5
- CVE-2026-102263 MEDIUM 4.7
- CVE-2026-102414 LOW 3.7
- CVE-2026-102422 HIGH 8.1
- CVE-2026-102247 MEDIUM 6.8
- CVE-2026-96326 HIGH 7.2
- CVE-2026-101858 MEDIUM 4.7
- CVE-2026-101860 HIGH 8.8
- CVE-2026-101280 HIGH 7.3
- CVE-2026-101281 HIGH 7.3