Remote Code Execution Vulnerability in OPNsense Firewall
CVE-2026-44193

9.1CRITICAL

Key Information:

Vendor

Opnsense

Status
Vendor
CVE Published:
13 May 2026

What is CVE-2026-44193?

A vulnerability in the OPNsense firewall, specifically in the XMLRPC method opnsense.restore_config_section, allows for unsanitized user input that could lead to remote code execution. This flaw impacts versions prior to 26.1.7 and poses significant security risks, enabling malicious actors to execute arbitrary commands within the affected environment. The issue has been resolved in version 26.1.7.

Affected Version(s)

core < 26.1.7

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.