Path traversal in OPNsense - #VU134541
Published: June 15, 2026
OPNsense
Detailed vulnerability description
The vulnerability allows a remote user to create root-owned symlinks outside the intended IPsec CA directory.
The vulnerability exists due to path traversal in Trust CA refid handling in IPsec CA file generation when processing attacker-controlled CA references during IPsec reconfiguration. A remote user can supply a crafted refid value to create root-owned symlinks outside the intended IPsec CA directory.
Exploitation requires access to Trust CA management and IPsec configuration, and the created symlink retains a fixed .crt suffix.