PT-2026-67505 · Deciso B.V.+1 · Opnsense+1

·

CVE-2026-49131

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OPNsense versions prior to 26.1.9
Description Authenticated attackers with firewall rule management privileges can perform a stored cross-site scripting attack. By embedding malicious HTML or JavaScript payloads into the firewall rule description field via the filter API endpoint, the unsanitized value is stored and subsequently rendered by the default cell formatter in opnsense bootgrid.js. This occurs because raw cell content is assigned to innerHTML, which executes the injected scripts in the browser of any authenticated user viewing the Firewall Rules page, potentially leading to session hijacking or credential theft.
Recommendations Update OPNsense to version 26.1.9 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49131

Affected Products

Opnsense
Core