LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-34578

CVE-2026-34578 - Vulnerability Analysis

HighCVSS: 8.2

Last Updated: April 9, 2026

OPNsense - LDAP Injection & Authentication Bypass

Published: April 9, 2026Updated: April 9, 2026Remote Exploitable

Overview

OPNsense < 26.1.6 contains an LDAP injection caused by unescaped username input in the LDAP authentication connector, letting unauthenticated attackers enumerate valid usernames and bypass group restrictions, exploit requires no authentication.

Severity & Score

Severity: High
CVSS Score: 8.2

Impact

Unauthenticated attackers can enumerate LDAP usernames and bypass group membership restrictions to authenticate as any user with a known password.

Mitigation

Update to version 26.1.6 or later.

Details

CVE ID
CVE-2026-34578
Severity
High
CVSS Score
8.2
Type
ldap_injection
Status
new

CWE

  • CWE-90

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N