CVE-2026-44195: OPNsense: Authentication lockout bypass
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockouthandler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword ("Accepted" or "Successful login") between normal brute-force attempts, an attacker can prevent the failure counter from ever reaching the lockout threshold. This vulnerability is fixed in 26.1.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44195?
CVE-2026-44195 is classified as a high severity vulnerability, as it allows unauthenticated attackers to bypass authentication lockout mechanisms.
How do I fix CVE-2026-44195?
To fix CVE-2026-44195, upgrade OPNsense to version 26.1.7 or later.
Who is affected by CVE-2026-44195?
All users of OPNsense versions prior to 26.1.7 are affected by CVE-2026-44195.
What type of vulnerability is CVE-2026-44195?
CVE-2026-44195 is a logic flaw vulnerability related to authentication lockout management.
Can CVE-2026-44195 be exploited remotely?
Yes, CVE-2026-44195 can be exploited remotely by an unauthenticated attacker.