Command injection in OPNsense - #VU142551

 

Command injection in OPNsense - #VU142551

Published: August 14, 2026


Vulnerability identifier: #VU142551
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary OpenVPN management protocol commands.

The vulnerability exists due to command injection in the OpenVPN session kill endpoint and backend kill_session.py script when handling a crafted session_id parameter containing newline characters. A remote privileged user can send a specially crafted request to execute arbitrary OpenVPN management protocol commands.

The injected commands are written to the OpenVPN management unix socket as root, and exploitation can terminate, restart, or otherwise control the VPN daemon. An authenticated VPN peer may also reach the same injection path through a crafted certificate common name when an operator kills its session.


Affected software

OPNsense

Remediation

Install security update from vendor's website.

OPNsense - update to 26.7.2

External References

Related Security Bulletins