Authorization bypass through user-controlled key in OPNsense - #VU139365

 

Authorization bypass through user-controlled key in OPNsense - #VU139365

Published: July 26, 2026


Vulnerability identifier: #VU139365
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose private keys and potentially impersonate clients or services.

The vulnerability exists due to authorization bypass through user-controlled key in OPNsense\OpenVPN\Api\ExportController when handling download requests with a route-supplied certificate reference. A remote user can submit a crafted download request with an unlisted certificate reference to disclose private keys and potentially impersonate clients or services.

The download endpoint does not verify that the requested certificate belongs to the selected server CA, the current user, or any export-visible account row.


Affected software

OPNsense

Remediation

Install security update from vendor's website.

OPNsense - update to 26.7.1

External References

Related Security Bulletins