Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34578

28
FAUCET Score

OVERVIEW CVE-2026-34578 is an LDAP injection vulnerability in OPNsense, a FreeBSD-based firewall and routing platform, affecting versions prior to 26.1.6. The flaw exists in the LDAP authentication connector, which fails to properly sanitize user input by not calling ldap_escape() when processing login credentials. SEVERITY This vulnerability carries a CVSS score of 8.2 (HIGH) with a network-based attack vector requiring no authentication or user interaction. An unauthenticated attacker can exploit the vulnerability to enumerate valid LDAP usernames and potentially bypass group membership restrictions to authenticate as any LDAP user with a known password. The impact includes significant confidentiality compromise and limited integrity impact, though system availability remains unaffected. EXPLOITATION STATUS The vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows minimal community attention with an EPSS score of 0.00208, indicating lower likelihood of near-term exploitation relative to the overall CVE population. No active exploitation or readily available exploit code has been reported, and the vulnerability remains in an inactive status on threat tracking lists.

Impacted Technologies

VendorProductVersion(s)CPE
< 26.1.6CPE matchmatch criteria
cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
34.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 13th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / opnsense/core/commit/016f66cb4620cd48183fa97843f343bb71813c6e
Patch
github.com / opnsense/core/security/advisories/GHSA-jpm7-f59c-mp54
ExploitMitigationVendor Advisory