CVE-2026-53605
Received Received - Intake

Local Privilege Escalation in Reachy Mini ISO for Wireless

Vulnerability report for CVE-2026-53605, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
reachy mini_wireless_os_image to 0.2.4 (inc)
pollen_robotics reachy_mini_os to 0.2.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-250 The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-53605 is a local privilege escalation vulnerability in Reachy Mini Wireless OS versions prior to 0.2.4. It stems from an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl without subcommand restrictions. This allows any process running as pollen to escalate privileges to root by exploiting systemd commands.

Detection Guidance

Check if the pollen user (uid 1000) has passwordless sudo access to /usr/bin/systemctl by inspecting /etc/sudoers or /etc/sudoers.d/. Run 'sudo -l -U pollen' to list allowed commands. If it shows unrestricted sudo access to systemctl, the system is vulnerable.

Impact Analysis

An attacker with local access can gain full root privileges on the device in three commands. This enables reading sensitive files like /etc/shadow, installing persistent backdoors, modifying firmware updates, bypassing safety limits, moving laterally across networks, and deleting logs. The attack requires no additional vulnerabilities or user interaction.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and system integrity. It allows unauthorized root access, which could lead to unauthorized data access, modification, or deletion. Organizations using affected systems may face penalties for failing to maintain adequate security controls under standards like GDPR and HIPAA.

Mitigation Strategies

Upgrade to Reachy Mini OS version 0.2.4 or later by re-flashing the device with the patched image. As a temporary workaround, remove the broad sudoers entry for pollen and replace it with a scoped one that restricts commands to specific arguments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53605. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart