ISOMAN

CVE

CVE-2026-44193

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.

Severity
CRITICAL
CVSS
9.1
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
OPNsense26.1.2 amd64 dvdunknownsource

References

  1. https://github.com/opnsense/core/security/advisories/GHSA-xxp9-93cr-x54p
  2. https://github.com/opnsense/core/security/advisories/GHSA-xxp9-93cr-x54p