OPNsense XPATH Injection (CVE-2026-53582)
Posted by evan on Jul 06SUMMARY: a stored XPATH injection allows any user with just ca
manager/certificate manager perms to leak any secret key/any value in
config.xml, thus achieving privilege escalation and potentially remote
code execution. this can also likely be chained via csrf and some
clever hiding. see
https://github.com/opnsense/core/security/advisories/GHSA-xww7-76m6-mh2r == VULN ==
the primary vulnerable sink is here: $refcount =...