Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-53605 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-250Execution with Unnecessary Privileges[email protected]
CWE-269Improper Privilege Management[email protected]

Affected Products

ProductVersions
Pollen Robotics Reachy Mini ISO
< 0.2.4 (semver)

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Upgrade: 0.2.4moderate effort
  • Workaround:moderate effort

    Log in as root (or via sudo -i) and execute the following commands: 1. Remove the overly broad grant (if present): rm -f /etc/sudoers.d/010_pi-nopasswd 2. Install the scoped grant: cat > /etc/sudoers.d/010-pollen-reachy << 'EOF' Cmnd_Alias REACHY = \ /usr/bin/systemctl restart reachy-mini-daemon, \ /usr/bin/systemctl restart reachy-mini-bluetooth, \ /usr/sbin/rfkill unblock bluetooth, \ /usr/sbin/rfkill unblock wifi, \ /usr/sbin/shutdown -h now, \ /bluetooth/commands/HOTSPOT.sh, \ /bluetooth/commands/WIFI_RESET.sh, \ /bluetooth/commands/SOFTWARE_RESET.sh, \ /bluetooth/commands/RESTART_DAEMON.sh pollen ALL=(root) NOPASSWD: REACHY EOF chmod 0440 /etc/sudoers.d/010-pollen-reachy 3. Validate the resulting sudoers configuration: visudo -c Verify the workaround: as the pollen user, run "sudo -n -l 2>&1 | grep systemctl". The only matching entries should be the two pinned restart lines. If bare /usr/bin/systemctl (no subcommand) still appears in any sudoers file, the escalation primitive is still present and the workaround has not been applied correctly. Important caveat: the scoped grant is only safe if the /bluetooth/commands/*.sh scripts remain root-owned and not writable by pollen — otherwise an attacker can rewrite a permitted script and run sudo <script> to obtain root by a different path. Verify with: ls -la /bluetooth/commands/ # Each script should be owned by root:root and not group/world writable.

Change History

1 change record found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-53605
NVD Published Date:
Sep 30, 2026
NVD Last Modified:
Sep 30, 2026
Source:
[email protected]
CVE-2026-53605 Details - Not Deferred