๐Ÿ” CVE Alert

CVE-2026-49131

MEDIUM 5.4

OPNsense < 26.1.9 Stored XSS via Firewall Rule Description Field

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule description field via the filter API endpoint. The unsanitized description value is persisted and later rendered through the default cell formatter in opnsense_bootgrid.js, which assigns raw cell content to innerHTML, causing injected scripts to execute in the browser of any authenticated user who views the Firewall Rules page, enabling session hijacking or credential theft.

CWE CWE-79
Vendor deciso b.v.
Product opnsense
Published Aug 3, 2026
Last Updated Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for deciso b.v. opnsense

Be the first to know when new medium vulnerabilities affecting deciso b.v. opnsense are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Deciso B.V. / OPNsense
0 < 26.1.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.opnsense.org: https://docs.opnsense.org/releases/CE_26.1.html#june-02-2026 github.com: https://github.com/opnsense/core/commit/b11d6b340716e240868ab19a369e058a46f0876f vulncheck.com: https://www.vulncheck.com/advisories/opnsense-stored-xss-via-firewall-rule-description-field

Credits

Alex Williams from Pellera Technologies VulnCheck