CVE-2026-45158Disclosure(opnsense / opnsense)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch opnsense opnsense systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system. This vulnerability is fixed in 26.1.8.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opnsense

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-14); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
opnsense

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-13: 1Mentions · 2026-05-14: 2Mentions · 2026-05-15: 1Mentions · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-15: 1Exploit Tool / Code · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 2Technical Details · 2026-05-15: 1Technical Details · 2026-05-23: 105-1305-1405-1505-23
Signal classification3 categories
Disclosure
360.0%
PoC
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-131
Disclosure1
2026-05-142
Disclosure1PoC1
2026-05-151
Disclosure1
2026-05-231
General1
Full discourse5 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-44194 & CVE-2026-45158: Two RCE vulnerabilities in OPNsense, 9.1 rating 🔥 Two vulnerabilities in OPNsense allows an authenticated attacker to execute arbitrary code as root on the firewall host via User management system (CVE-2026-44194) and DHCP Config (CVE-2026-45158). PoC already available! 👉 https://nt.ls/S0qIg

    Post summary

    The tweet announces two high‑severity RCE vulnerabilities in OPNsense, provides technical details, and references an available PoC.

    211039143.1K
    7.6K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Public PoC for OPNsense CVE-2026-44194 and CVE-2026-45158. Critical flaws allow root command execution via DHCP and User sync. Update to 26.1.8 now! #OPNsense #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #CVE #Firewall #OpenSource #RootExploit #PoC https://securityonline.info/opnsense-critical-root-rce-cve-2026-44194-poc-disclosure/ https://t.co/h7ZLLVxxln

    Post summary

    Public PoC releases for OPNsense CVE-2026-44194 and CVE-2026-45158 are shared, detailing critical root command execution flaws, along with an available patch version 26.1.8.

    050134981
    12.5K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-45158: OPNsense DHCP Configuration Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04hKNXc0

    Post summary

    The link announces the OPNsense DHCP configuration injection vulnerability (CVE‑2026‑45158) and hints at business implications, but offers no PoC, exploit code, active exploitation evidence, patch, or detailed technical breakdown beyond the vulnerability type.

    0000040
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-45158 Remote Code Execution in OPNsense Prior to 26.1.8 via DHCP Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45158

    Post summary

    CVE‑2026‑45158 is an RCE flaw in OPNsense versions before 26.1.8 involving DHCP configuration, but the text offers no PoC, exploit code, or evidence of active exploitation.

    0000051
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45158 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, wh… https://www.cve.org/CVERecord?id=CVE-2026-45158

    Post summary

    The post announces that OPNsense before version 26.1.8 is vulnerable due to unsanitized input in the DHCP configuration, without providing a PoC, exploit, or patch information.

    0000099
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopnsenseopnsense---

Explore more