{"id":"CVE-2026-61876","title":"LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup","summary":"LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-79"],"published":"2026-07-12","updated":"2026-07-12","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-61876","references":[{"url":"https://github.com/openwrt/luci/security/advisories/GHSA-686p-p8p9-x6fh","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/luci-dhcpv6-lease-hostname-stored-cross-site-scripting","label":"disclosure@vulncheck.com"}],"tags":["nvd","exploit-available"],"ingestedAt":"2026-07-12T12:20:14.107Z","epss":0.01277,"epssPercentile":0.68199,"exploitAvailable":true,"exploits":{"exploitdb":true,"checkedAt":"2026-09-21T15:29:54.811Z"},"slug":"CVE-2026-61876","body":"## Overview\n\nLuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[{"seq":130,"id":"CVE-2026-61876","ts":1786564763557,"field":"exploit_available","old":"false","new":"true"}]}