Stored Cross-Site Scripting in OPNsense by Deciphering Firewall Rule Descriptions
CVE-2026-49131

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 August 2026

What is CVE-2026-49131?

A vulnerability exists in OPNsense prior to version 26.1.9 that allows authenticated users with privileges to manage firewall rules to inject arbitrary HTML or JavaScript. This occurs when payloads are embedded into the firewall rule description, leading to potential session hijacking or credential theft when the data is rendered on the Firewall Rules page. The unsanitized description is stored and later displayed, executing the embedded scripts in the browsers of authenticated users.

Affected Version(s)

OPNsense 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams from Pellera Technologies
VulnCheck
.