CVE-2026-53581

Source
https://cve.org/CVERecord?id=CVE-2026-53581
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53581.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53581
Aliases
  • GHSA-872g-g543-j37m
Published
2026-09-08T23:02:07Z
Modified
2026-09-11T03:31:01Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H CVSS Calculator
Summary
ntp: write path traversal
Details

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape the intended directory and force the system to write user-controlled data to any file on the filesystem. Version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core patch the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22",
        "CWE-73"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53581.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "< 26.4_20"
                },
                {
                    "last_affected": "< 26.4_20"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/opnsense/core

Affected ranges

Type
GIT
Repo
https://github.com/opnsense/core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "26.1.9"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

15.*
15.1
15.1.1
15.1.10
15.1.10.2
15.1.11
15.1.11.1
15.1.11.2
15.1.11.3
15.1.11.4
15.1.12
15.1.2
15.1.3
15.1.4
15.1.5
15.1.6
15.1.6.1
15.1.7
15.1.7.1
15.1.7.2
15.1.8
15.1.8.1
15.1.8.2
15.1.8.3
15.1.8.4
15.1.9
15.1.9.1
15.1.9.2
15.7
16.*
16.7.a
16.7.b
16.7.r
17.*
17.1.a
17.1.b
17.1.r
17.7.a
17.7.b
17.7.r
18.*
18.1.a
18.1.b
18.1.r
18.7.a
18.7.b
18.7.r
19.*
19.1.a
19.1.b
19.1.r
19.7.a
19.7.b
19.7.r
20.*
20.1.a
20.1.b
20.1.r
20.7.a
20.7.b
20.7.r
21.*
21.1.a
21.1.b
21.1.r
21.7.a
21.7.b
21.7.r
22.*
22.1.a
22.1.b
22.1.r
22.7.a
22.7.b
22.7.r
23.*
23.1.a
23.1.b
23.1.r
23.7.a
23.7.b
23.7.r
24.*
24.1.a
24.1.b
24.1.r
24.7.a
24.7.b
24.7.r
25.*
25.1.a
25.1.b
25.1.r
25.7.a
25.7.b
25.7.r
26.*
26.1
26.1.1
26.1.2
26.1.3
26.1.4
26.1.5
26.1.6
26.1.7
26.1.8
26.1.a
26.1.b
26.1.r
26.1.r1
26.1.r2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53581.json"