CVE-2026-44194General(opnsense / opnsense)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch opnsense opnsense systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formatting their malicious payload as a compliant email address, allowing shell commands to reach the underlying operating system. The flaw exists in the local user synchronization flow, within core/src/opnsense/scripts/auth/sync_user.php. This vulnerability is fixed in 26.1.8.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opnsense

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-05-14); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
opnsense

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-05-13: 1Mentions · 2026-05-14: 3Mentions · 2026-05-15: 1Mentions · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-14: 2PoC Mentioned / Linked · 2026-05-15: 1Exploit Tool / Code · 2026-05-15: 1Patch / Workaround · 2026-05-14: 2Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 3Technical Details · 2026-05-15: 1Technical Details · 2026-05-23: 105-1305-1405-1505-23
Signal classification4 categories
General
233.3%
PoC
233.3%
Disclosure
116.7%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-131
General1
2026-05-143
Disclosure1Patch1PoC1
2026-05-151
PoC1
2026-05-231
General1
Full discourse6 posts
  • Netlas.io@Netlas_io
    PoC

    CVE-2026-44194 & CVE-2026-45158: Two RCE vulnerabilities in OPNsense, 9.1 rating 🔥 Two vulnerabilities in OPNsense allows an authenticated attacker to execute arbitrary code as root on the firewall host via User management system (CVE-2026-44194) and DHCP Config (CVE-2026-45158). PoC already available! 👉 https://nt.ls/S0qIg

    Post summary

    Two newly disclosed RCE vulnerabilities (CVE‑2026‑44194 and CVE‑2026‑45158) in OPNsense allow authenticated attackers to gain root access, with PoC code already available via the provided link.

    211039143.1K
    7.6K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Public PoC for OPNsense CVE-2026-44194 and CVE-2026-45158. Critical flaws allow root command execution via DHCP and User sync. Update to 26.1.8 now! #OPNsense #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #CVE #Firewall #OpenSource #RootExploit #PoC https://securityonline.info/opnsense-critical-root-rce-cve-2026-44194-poc-disclosure/ https://t.co/h7ZLLVxxln

    Post summary

    The post announces a publicly available PoC for CVE-2026-44194 and CVE-2026-45158, highlights critical RCE details, and urges users to apply the 26.1.8 patch.

    050134981
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    OPNsenseに重大(Critical)な脆弱性2件。CVE-2026-44194はWebインターフェースのユーザ名にメールアドレスを指定した際のOSコマンドインジェクション。CVE-2026-45158はDHCP構成からのOSコマンドインジェクション。いずれも要高権限。修正済み。 https://securityonline.info/opnsense-critical-root-rce-cve-2026-44194-poc-disclosure/

    Post summary

    The post reports two critical OS command injection CVEs in OPNsense, provides a link to a proof‑of‑concept disclosure, and confirms that patches are already in place.

    0101622.0K
    7.6K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-44194: OPNsense Firewall Remote Code Execution - What It Means for Your Business and How to Respond https://hubs.li/Q04hKrs50

    Post summary

    The post references CVE-2026-44194 and notes it as a remote code execution flaw in OPNsense Firewall, but provides no PoC, exploit code, active exploitation evidence, or patch details.

    0000037
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44194 Authenticated Remote Code Execution in OPNsense Prior to Version 26.1.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44194

    Post summary

    CVE‑2026‑44194 is an authenticated remote code execution vulnerability affecting OPNsense versions earlier than 26.1.8; the snippet reports the vulnerability but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000052
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-44194 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a u… https://www.cve.org/CVERecord?id=CVE-2026-44194

    Post summary

    A brief announcement of an authenticated RCE vulnerability in OPNsense before version 26.1.8, with no mention of exploits, patches, or active use.

    0000090
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopnsenseopnsense---

Explore more