CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69095

highCVSS 7.5covered by 1 sourcefirst seen 2026-08-03
OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the intended directory and read sensitive files accessible to the CGI process.

⚡ Watch CVE-2026-69095

Get an email if CVE-2026-69095 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-69095

CVE.org record

Embed the live status

CVE-2026-69095 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69095 status](https://www.csirts.com/badge/CVE-2026-69095)](https://www.csirts.com/cve/CVE-2026-69095)