An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.