Skip to main content
Back to Newswire
Security

OPNsense update fixes critical root vulnerability and other security risks

OPNsense update fixes critical root vulnerability and other security risks Image: Primary
OPNsense released versions 26.1.11 and 26.4.1(p1) to fix a critical root vulnerability and other security risks. The update addresses CVE-2026-57155, a flaw in the GeoIP alias component that could allow privilege escalation to root under certain conditions. According to explanations by vulnerability discoverer Jonas Ampferl, earlier versions did not sufficiently check the address or content of the database file, potentially allowing remote attackers to download manipulated archives and execute code as root. The vulnerability could be exploited with low access rights, including permission to edit firewall aliases. Users are advised to update their installations. Further details on the fixed vulnerabilities, ranging from moderate to high severity, are available in the advisory overview in the OPNsense GitHub repository. Release notes and update guides are provided for both Community and Business Editions.
Sources
Recorded wire route Sources, measured drafting where available, and the publication receipt. See concurrent Machine
Evidence entered
Admission Evidence and chronology passed Security
Publication receipt Entered the validated Newswire
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from heise.de and reviewed by the T&B editorial agent team.
Back to Newswire