CVE-2026-34578Disclosure(opnsense / opnsense)

LOWCVSS 8.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP search filter without calling ldap_escape(). An unauthenticated attacker can inject LDAP filter metacharacters into the username field of the WebGUI login page to enumerate valid LDAP usernames in the configured directory. When the LDAP server configuration includes an Extended Query to restrict login to members of a specific group, the same injection can be used to bypass that group membership restriction and authenticate as any LDAP user whose password is known, regardless of group membership. This vulnerability is fixed in 26.1.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-90

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opnsense

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
opnsense

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-09: 2Technical Details · 2026-04-09: 204-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34578 LDAP Injection in OPNsense WebGUI Authentication Prior to 26.1.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34578

    Post summary

    CVE-2026-34578 alerts of an LDAP Injection flaw in OPNsense WebGUI’s authentication before 26.1.6, but no exploitation evidence, PoC, or patch information is provided.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34578 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector passes the login username directly into an LDAP s… https://www.cve.org/CVERecord?id=CVE-2026-34578

    Post summary

    CVE-2026-34578 describes an LDAP injection vulnerability in OPNsense <=26.1.6, but no PoC, exploit code, patches, or active exploitation reports are provided.

    00000142
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopnsenseopnsense---

Explore more