CVE-2026-53581

    Dashboard / Vulnerabilities / CVE-2026-53581

    CVE-2026-53581

    Published: 8 Sept 2026Last Modified: 11 Sept 2026

    Summary: ntp: write path traversal

    Details: OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape the intended directory and force the system to write user-controlled data to any file on the filesystem. Version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core patch the issue.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    26.1.8
    26.1.6
    26.1.7
    26.1.5
    26.1.4
    26.1.3
    26.1.2
    26.1.1
    26.1
    26.1.r2
    26.1.r1
    26.1.r
    26.1.b
    26.1.a

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-53581 | CVE-DB