PT-2026-67506 · Opnsense · Opnsense

·

CVE-2026-49132

·

Published

2026-08-03

·

Updated

2026-08-04

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OPNsense versions prior to 26.1.9
Description Authenticated attackers can perform a stored cross-site scripting attack by injecting arbitrary HTML or JavaScript into the certificate description field. This occurs via the trust certificate API, where the unsanitized description value is stored and subsequently rendered in the Dashboard Certificates widget through Certificates.js. The script executes in the browser of any authenticated user viewing the Dashboard because the raw value is interpolated into HTML attribute and text content sinks without proper encoding, potentially leading to session hijacking or credential theft.
Recommendations Update OPNsense to version 26.1.9 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49132

Affected Products

Opnsense