A remote, authenticated attacker can exploit a vulnerability in OPNsense to disclose sensitive information. The CVSS base score is 7.1 (High). Affected versions are all OPNsense releases prior to version 26.1.10, and users must upgrade to OPNsense 26.1.10 to remediate the issue.
[WID-SEC-2026-1917] OPNsense: Schwachstelle ermöglicht Offenlegung von Informationen CVSS Base Score 7.1 (hoch) CVSS Temporal Score 6.4 (mittel) Remoteangriff ja Datum 14.06.2026 Stand 15.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges Produktbeschreibung OPNsense ist eine freie Firewall-Distribution auf Basis von FreeBSD. Produkte 14.06.2026 Open Source OPNsense <26.1.10 Angriff Angriff Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in OPNsense ausnutzen, um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben