OVERVIEW CVE-2026-34578 is an LDAP injection vulnerability in OPNsense, a FreeBSD-based firewall and routing platform, affecting versions prior to 26.1.6. The flaw exists in the LDAP authentication connector, which fails to properly sanitize user input by not calling ldap_escape() when processing login credentials. SEVERITY This vulnerability carries a CVSS score of 8.2 (HIGH) with a network-based attack vector requiring no authentication or user interaction. An unauthenticated attacker can exploit the vulnerability to enumerate valid LDAP usernames and potentially bypass group membership restrictions to authenticate as any LDAP user with a known password. The impact includes significant confidentiality compromise and limited integrity impact, though system availability remains unaffected. EXPLOITATION STATUS The vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows minimal community attention with an EPSS score of 0.00208, indicating lower likelihood of near-term exploitation relative to the overall CVE population. No active exploitation or readily available exploit code has been reported, and the vulnerability remains in an inactive status on threat tracking lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.1.6CPE matchmatch criteria | cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.