CVE-2026-44193
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restoreconfigsection fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44193.json, https://github.com/opnsense/core/security/advisories/GHSA-xxp9-93cr-x54p, https://nvd.nist.gov/vuln/detail/CVE-2026-44193