CVE-2026-53605 Details
Description
Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.
A local privilege escalation vulnerability has been identified in the Pollen Robotics Reachy Mini Wireless operating system, specifically in versions prior to 0.2.4. The issue arises from an overly broad sudoers entry that grants the pollen daemon user (UID 1000) passwordless sudo access to '/usr/bin/systemctl' without any restrictions on subcommands or arguments. This misconfiguration allows processes running as the pollen user to gain full root access (UID 0) on the device with just three commands, without requiring any additional vulnerabilities or user interaction. The escalation is achieved by exploiting the unrestricted sudo access to systemctl, enabling an attacker to create a root-owned symlink for an attacker-controlled unit file and execute it as root.
Users can upgrade to Reachy Mini OS version 0.2.4 or later, which includes the necessary fix. For those unable to upgrade immediately, the same fix can be applied manually by removing the broad sudoers grant and replacing it with a scoped entry that limits the commands the pollen user can execute as root. After applying the workaround, it's important to verify that the sudoers configuration is correct and that the Bluetooth command scripts remain owned by root and not writable by the pollen user.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/pollen-robotics/reachy-mini-os/commit/cee4076f36bd95a2a6b894a56a48c7e971e75445 | [email protected] | Source CodeVendor |
| https://github.com/pollen-robotics/reachy-mini-os/releases/tag/v0.2.4 | [email protected] | Release NotesVendor |
| https://github.com/pollen-robotics/reachy-mini-os/security/advisories/GHSA-7rhg-9v48-x3h2 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-250 | Execution with Unnecessary Privileges | [email protected] |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Pollen Robotics Reachy Mini ISO | < 0.2.4 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion