Incorrect authorization in OPNsense - #VU139364
Published: July 26, 2026
Vulnerability details
The vulnerability allows a remote user to make persistent configuration changes.
The vulnerability exists due to incorrect authorization in API controllers using manual Config::save() paths when handling crafted API requests to affected endpoints. A remote user can send a crafted request to make persistent configuration changes.
Exploitation requires an authenticated account assigned the user-config-readonly deny privilege together with an affected page privilege.