CVE-2026-53581: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in opnsense core
A critical path traversal vulnerability (CWE-22) exists in the NTP configuration module of OPNsense core prior to version 26.1.9. This flaw allows an attacker with access to the NTP configuration and high privileges to overwrite arbitrary files on the system as root by manipulating GPS or PPS serial port parameters. The vulnerability is patched in OPNsense core version 26.1.9 and backend version 26.4_20.
AI Analysis
Technical Summary
OPNsense core, a FreeBSD-based firewall and routing platform, contains a path traversal vulnerability in its NTP configuration module before version 26.1.9. An attacker with access to the NTP configuration and high privileges can exploit this vulnerability by manipulating GPS or PPS serial port parameters to escape the intended directory restrictions and write user-controlled data to arbitrary files on the filesystem with root privileges. This vulnerability is tracked as CVE-2026-53581 and has a CVSS 3.1 base score of 9.0 (critical). The issue is fixed in version 26.1.9 of opnsense/core and version 26.4_20 of the backend.
Potential Impact
Successful exploitation allows an attacker with high privileges and access to the NTP configuration to overwrite arbitrary files on the system as root, potentially leading to full system compromise, data corruption, or denial of service. The vulnerability affects confidentiality, integrity, and availability of the system.
Mitigation Recommendations
Upgrade to OPNsense core version 26.1.9 or later and backend version 26.4_20 or later to apply the official fix. No other mitigation or temporary workaround is documented. Patch status is confirmed by the vendor advisory indicating these versions fix the issue.
CVE-2026-53581: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in opnsense core
Description
A critical path traversal vulnerability (CWE-22) exists in the NTP configuration module of OPNsense core prior to version 26.1.9. This flaw allows an attacker with access to the NTP configuration and high privileges to overwrite arbitrary files on the system as root by manipulating GPS or PPS serial port parameters. The vulnerability is patched in OPNsense core version 26.1.9 and backend version 26.4_20.
CVSS v3.1
Score 9.0critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OPNsense core, a FreeBSD-based firewall and routing platform, contains a path traversal vulnerability in its NTP configuration module before version 26.1.9. An attacker with access to the NTP configuration and high privileges can exploit this vulnerability by manipulating GPS or PPS serial port parameters to escape the intended directory restrictions and write user-controlled data to arbitrary files on the filesystem with root privileges. This vulnerability is tracked as CVE-2026-53581 and has a CVSS 3.1 base score of 9.0 (critical). The issue is fixed in version 26.1.9 of opnsense/core and version 26.4_20 of the backend.
Potential Impact
Successful exploitation allows an attacker with high privileges and access to the NTP configuration to overwrite arbitrary files on the system as root, potentially leading to full system compromise, data corruption, or denial of service. The vulnerability affects confidentiality, integrity, and availability of the system.
Mitigation Recommendations
Upgrade to OPNsense core version 26.1.9 or later and backend version 26.4_20 or later to apply the official fix. No other mitigation or temporary workaround is documented. Patch status is confirmed by the vendor advisory indicating these versions fix the issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-09T19:11:53.484Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa098c9acd9273b495cca85
Added to database: 09/08/2026, 23:22:49 UTC
Last enriched: 09/08/2026, 23:37:04 UTC
Last updated: 09/09/2026, 00:13:50 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.