Description
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword ("Accepted" or "Successful login") between normal brute-force attempts, an attacker can prevent the failure counter from ever reaching the lockout threshold. This vulnerability is fixed in 26.1.7.
Published: 2026-05-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A logic flaw in OPNsense’s lockout_handler allows an unauthenticated attacker to reset the authentication failure counter for their IP address. By inserting a crafted username that contains a success keyword such as "Accepted" or "Successful login" between normal brute‑force attempts, the system mistakenly treats the login attempt as successful, preventing the counter from ever reaching the lockout threshold. As a result, an attacker can continue to send credentials indefinitely, potentially discovering valid credentials over time.

Affected Systems

The vulnerability impacts all OPNsense core installations older than version 26.1.7. The affected component is the lockout_handler responsible for tracking authentication failures. Users running versions prior to 26.1.7 should be aware that the logic flaw exists in the core package.

Risk and Exploitability

With a CVSS score of 5.3, the vulnerability is classified as moderate severity. No EPSS score is available and the issue is not listed in CISA’s KEV catalog. The attack vector is an unauthenticated remote attacker able to send crafted authentication requests over the network; no privileged access is required. Because the flaw is already fixed in 26.1.7, the risk is effectively mitigated once the system is updated.

Generated by OpenCVE AI on May 13, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OPNsense to version 26.1.7 or later to apply the lockout_handler fix.
  • If an upgrade cannot occur immediately, consider disabling remote authentication or enforcing stricter account lockout policies at the firewall level to limit brute‑force attempts.
  • Enable detailed logging of authentication activity and monitor for repeated failed attempts or unusual username patterns to detect ongoing exploitation.

Generated by OpenCVE AI on May 13, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 15 May 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Opnsense opnsense
CPEs cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:*
Vendors & Products Opnsense opnsense

Thu, 14 May 2026 14:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Opnsense
Opnsense core
Vendors & Products Opnsense
Opnsense core

Wed, 13 May 2026 22:15:00 +0000

Type Values Removed Values Added
Description OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication failure counter for their IP address. By interjecting a crafted username containing a success keyword ("Accepted" or "Successful login") between normal brute-force attempts, an attacker can prevent the failure counter from ever reaching the lockout threshold. This vulnerability is fixed in 26.1.7.
Title OPNsense: Authentication lockout bypass
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-05-14T13:46:30.721Z

Reserved: 2026-05-05T15:13:47.570Z

Link: CVE-2026-44195

cve-icon Vulnrichment

Updated: 2026-05-14T13:46:18.566Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-13T22:16:43.820

Modified: 2026-05-15T16:06:30.720

Link: CVE-2026-44195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T23:30:06Z

Weaknesses