Improper Restriction of Excessive Authentication Attempts in OPNsense - #VU129775
Published: May 5, 2026
OPNsense
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication lockout protections.
The vulnerability exists due to improper restriction of excessive authentication attempts in the lockout_handler when processing authentication syslog events containing attacker-controlled usernames. A remote attacker can submit failed login attempts with a crafted username containing a success keyword to bypass authentication lockout protections.
This impacts both the WebGUI and ssh password login paths.