Unknown · Travelmate · CVE-2026-58652
**Name of the Vulnerable Software and Affected Versions**
luci-app-travelmate versions 2.4.5-r3 through 2.4.6-1
travelmate versions 2.4.5-r3 through 2.4.6-1
**Description**
A privilege-escalation flaw exists where a LuCI/rpcd session with write ACL for luci-app-travelmate is granted config-wide UCI write access to the travelmate configuration. Although the user interface restricts the auto-login script selection to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service, which runs as root, reads the raw UCI `script` and `script args` values and executes the path when the captive-portal auto-login branch `f check()` in travelmate-functions.sh is reached. An attacker with delegated write permissions can change `script` to /bin/sh and provide controlled arguments in `script args` to execute arbitrary commands as root.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.