Logic Flaw in OPNsense Firewall Allows Continuous Authentication Resets
CVE-2026-44195

5.3MEDIUM

Key Information:

Vendor

Opnsense

Status
Vendor
CVE Published:
13 May 2026

What is CVE-2026-44195?

A logic flaw in OPNsense Firewall's lockout_handler component allows unauthenticated attackers to manipulate the authentication failure counter. By injecting a crafted username that includes success keywords, such as 'Accepted' or 'Successful login,' attackers can prevent the failure counter from reaching the threshold necessary for a lockout. This vulnerability remains unaddressed until the release of version 26.1.7, which mitigates the issue by securing the authentication mechanism against such manipulation.

Affected Version(s)

core < 26.1.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.