Stored Cross-Site Scripting in OPNsense by Deciphering Firewall Rule Descriptions
CVE-2026-49131
5.1MEDIUM
What is CVE-2026-49131?
A vulnerability exists in OPNsense prior to version 26.1.9 that allows authenticated users with privileges to manage firewall rules to inject arbitrary HTML or JavaScript. This occurs when payloads are embedded into the firewall rule description, leading to potential session hijacking or credential theft when the data is rendered on the Firewall Rules page. The unsanitized description is stored and later displayed, executing the embedded scripts in the browsers of authenticated users.
Affected Version(s)
OPNsense 0
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Williams from Pellera Technologies
VulnCheck
