Remote Code Execution Vulnerability in OPNsense Firewall by Deciso
CVE-2026-44194
9.1CRITICAL
What is CVE-2026-44194?
OPNsense, a FreeBSD-based firewall and routing platform, is affected by an authenticated Remote Code Execution vulnerability that allows users with user-management privileges to execute arbitrary system commands as root. By exploiting input validation flaws, an attacker can format a malicious payload as a compliant email address, thus bypassing security measures and delivering shell commands directly to the operating system. This issue resides in the local user synchronization process and has been resolved in version 26.1.8.
Affected Version(s)
core < 26.1.8
