Junglewise Threat Intelligence

CVE-2026-44194: OPNsense OS command injection in user management

CVE-2026-44194 · Severity: critical · CVSS 9.1 · Published 2026-05-13

Technologies: OPNsense. Vendors: OPNsense.

Executive brief

OPNsense is a firewall and routing platform used to secure corporate and private networks. A security flaw allows an administrator with user-management permissions to execute malicious commands on the underlying operating system with the highest level of authority (root). This could lead to a complete takeover of the firewall, allowing an attacker to intercept network traffic, disable security protections, or gain a foothold in the internal network.

Technical details

An OS command injection vulnerability exists in OPNsense core within the local user synchronization script (core/src/opnsense/scripts/auth/sync_user.php). The root cause is the improper neutralization of the $username variable when passed to the mwexecf function, which executes shell commands. While the web interface and API validate usernames, they permit valid email addresses; an attacker can exploit this by wrapping shell metacharacters in quotes within the 'local-part' of an email address. This payload bypasses validation but is interpreted by the shell when the script invokes pluginctl. Successful exploitation requires high privileges (user-management) but results in arbitrary command execution as the root user. The issue is fixed in version 26.1.8 by properly parameterizing the shell command.

Affected products

  • OPNsense OPNsense core < 26.1.8

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-05-13: disclosed: CVE-2026-44194 published to NVD
  • 2026-05-13: patched: Vulnerability fixed in version 26.1.8

References

Related threats