Logic Flaw in OPNsense Firewall Allows Continuous Authentication Resets
CVE-2026-44195
5.3MEDIUM
What is CVE-2026-44195?
A logic flaw in OPNsense Firewall's lockout_handler component allows unauthenticated attackers to manipulate the authentication failure counter. By injecting a crafted username that includes success keywords, such as 'Accepted' or 'Successful login,' attackers can prevent the failure counter from reaching the threshold necessary for a lockout. This vulnerability remains unaddressed until the release of version 26.1.7, which mitigates the issue by securing the authentication mechanism against such manipulation.
Affected Version(s)
core < 26.1.7
