CVE-2026-44195 Details
Description
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword ("Accepted" or "Successful login") between normal brute-force attempts, an attacker can prevent the failure counter from ever reaching the lockout threshold. This vulnerability is fixed in 26.1.7.
A logic flaw in OPNsense's lockout handler allows unauthenticated attackers to manipulate the authentication failure counter for their IP address. This vulnerability is present in OPNsense versions through 26.1.6. The issue arises because the lockout handler, which tracks failed login attempts and bans offending IPs, incorrectly processes usernames that include success keywords like 'Accepted' or 'Successful login'. By inserting such usernames between regular brute-force attempts, an attacker can prevent the failure counter from reaching the lockout threshold, thereby bypassing a key security measure against credential stuffing attacks. This flaw affects both the WebGUI and SSH password logins.
Users are advised to update to OPNsense version 26.1.7, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/sopex/b9786e72e2a5d9b1bbd81ed8477c351b | CISA-ADP | Exploit |
| https://github.com/opnsense/core/security/advisories/GHSA-h3vx-4q27-rc42 | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| opnsense opnsense | < 26.1.7 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 14, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |