MEDIUM 5.1 NVD
CVE-2026-49132
OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedd
OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate API. The unsanitized description value is persisted and later rendered in the Dashboard Certificates widget through Certificates.js, which interpolates the raw value into HTML attribute and text content sinks without encoding, causing injected scripts to execute in the browser of any authenticated user who views the Dashboard, enabling session hijacking or credential theft.
References
- https://docs.opnsense.org/releases/CE_26.1.html#june-02-2026
- https://github.com/opnsense/core/commit/12b021ff11db38705e92ac4c9af5e07d602da6ba
- https://www.vulncheck.com/advisories/opnsense-stored-xss-via-certificate-description-field
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-08-03 via NVD.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.