CVE-2026-44194Opnsense · Opnsense
Vulnerability data via NVD (ingested)
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileges to execute arbitrary system commands as root. An attacker can bypass input validation by formatting their malicious payload as a compliant email address, allowing shell commands to reach the underlying operating system. The flaw exists in the local user synchronization flow, within core/src/opnsense/scripts/auth/sync_user.php. This vulnerability is fixed in 26.1.8.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-44194product:"Opnsense Opnsense"http.html:"Opnsense"More intel sources (5)
vuln:CVE-2026-44194vulnerabilities.cve_id: CVE-2026-44194CVE-2026-44194CVE-2026-44194"CVE-2026-44194" exploit -site:nvd.nist.gov