PT-2026-67506 · Opnsense · Opnsense
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OPNsense versions prior to 26.1.9
Description
Authenticated attackers can perform a stored cross-site scripting attack by injecting arbitrary HTML or JavaScript into the certificate description field. This occurs via the trust certificate API, where the unsanitized description value is stored and subsequently rendered in the Dashboard Certificates widget through
Certificates.js. The script executes in the browser of any authenticated user viewing the Dashboard because the raw value is interpolated into HTML attribute and text content sinks without proper encoding, potentially leading to session hijacking or credential theft.Recommendations
Update OPNsense to version 26.1.9 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opnsense