PT-2026-40826 · Opnsense · Opnsense

Published

2026-05-13

·

Updated

2026-05-14

·

CVE-2026-44193

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OPNsense versions prior to 26.1.7
Description OPNsense is a FreeBSD based firewall and routing platform. The XMLRPC method 'opnsense.restore config section' fails to sanitize user supplied input, which can lead to Remote Code Execution (RCE), a process where an attacker can execute arbitrary commands on the target machine.
Recommendations Update to version 26.1.7.

Exploit

Fix

RCE

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44193

Affected Products

Opnsense