Path Traversal Vulnerability in OPNsense Firewall
CVE-2026-53581

9CRITICAL

Key Information:

Vendor

Opnsense

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-53581?

A path traversal vulnerability exists in the NTP configuration module of OPNsense, a FreeBSD-based firewall and routing platform. This flaw allows an attacker with access to the NTP configuration to manipulate the GPS or PPS serial port parameters, enabling them to escape the intended directory. Consequently, the attacker can overwrite arbitrary files on the system with root user privileges, posing a significant risk to the integrity of the filesystem. The issue has been resolved in versions 26.1.9 of opnsense/core and 26.4_20 of BE/opnsense/core.

Affected Version(s)

core < 26.1.9 < 26.1.9

core < 26.4_20 < 26.4_20

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.