Executive brief
OPNsense is a firewall and routing platform used to secure corporate and private networks. A security flaw allows an administrator with user-management permissions to execute malicious commands on the underlying operating system with the highest level of authority (root). This could lead to a complete takeover of the firewall, allowing an attacker to intercept network traffic, disable security protections, or gain a foothold in the internal network.
Technical details
An OS command injection vulnerability exists in OPNsense core within the local user synchronization script (core/src/opnsense/scripts/auth/sync_user.php). The root cause is the improper neutralization of the $username variable when passed to the mwexecf function, which executes shell commands. While the web interface and API validate usernames, they permit valid email addresses; an attacker can exploit this by wrapping shell metacharacters in quotes within the 'local-part' of an email address. This payload bypasses validation but is interpreted by the shell when the script invokes pluginctl. Successful exploitation requires high privileges (user-management) but results in arbitrary command execution as the root user. The issue is fixed in version 26.1.8 by properly parameterizing the shell command.
Affected products
- OPNsense OPNsense core < 26.1.8
Timeline
- 2026-05-12: advisory: GitHub Security Advisory published
- 2026-05-13: disclosed: CVE-2026-44194 published to NVD
- 2026-05-13: patched: Vulnerability fixed in version 26.1.8