๐Ÿ” CVE Alert

CVE-2026-49132

MEDIUM 5.4

OPNsense < 26.1.9 Stored XSS via Certificate Description Field

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate API. The unsanitized description value is persisted and later rendered in the Dashboard Certificates widget through Certificates.js, which interpolates the raw value into HTML attribute and text content sinks without encoding, causing injected scripts to execute in the browser of any authenticated user who views the Dashboard, enabling session hijacking or credential theft.

CWE CWE-79
Vendor deciso b.v.
Product opnsense
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for deciso b.v. opnsense

Be the first to know when new medium vulnerabilities affecting deciso b.v. opnsense are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Deciso B.V. / OPNsense
0 < 26.1.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.opnsense.org: https://docs.opnsense.org/releases/CE_26.1.html#june-02-2026 github.com: https://github.com/opnsense/core/commit/12b021ff11db38705e92ac4c9af5e07d602da6ba vulncheck.com: https://www.vulncheck.com/advisories/opnsense-stored-xss-via-certificate-description-field

Credits

Alex Williams from Pellera Technologies VulnCheck