Path traversal in OPNsense - #VU134540
Published: June 15, 2026
OPNsense
Detailed vulnerability description
The vulnerability allows a remote user to create or overwrite root-owned files outside the intended IPsec certificate directories.
The vulnerability exists due to path traversal in Trust certificate refid handling in IPsec file generation when processing attacker-controlled certificate references during IPsec reconfiguration. A remote user can supply a crafted refid value to create or overwrite root-owned files outside the intended IPsec certificate directories.
Exploitation requires access to Trust certificate management and IPsec configuration, and the created files retain fixed .key and .crt suffixes.