Junglewise Threat Intelligence

CVE-2026-49132: OPNsense stored cross-site scripting in certificate description

CVE-2026-49132 · Severity: medium · CVSS 5.4 · Published 2026-08-03

Technologies: OPNsense. Vendors: OPNsense.

Executive brief

OPNsense is an open-source firewall management system used to protect and control network traffic. Before version 26.1.9, authenticated users could inject malicious code into certificate descriptions via the API. When other administrators view the Dashboard's Certificates widget, this injected code executes in their browsers, potentially allowing attackers to steal session credentials or hijack administrative accounts.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in OPNsense's certificate management API. An authenticated attacker can inject arbitrary JavaScript into the certificate description field via the trust certificate API endpoint. The unsanitized description value is persisted in the database and later rendered in the Dashboard Certificates widget (Certificates.js) without proper HTML encoding, causing the injected scripts to execute in the browser context of any authenticated user who accesses the Dashboard. The attack requires prior authentication but no additional user interaction. The fix was applied in version 26.1.9 by removing the unescaped data-tooltip attribute that rendered the description field.

Affected products

  • OPNsense OPNsense before 26.1.9

Timeline

  • 2026-08-03: disclosed
  • 2026-01-29: patched: Fixed in version 26.1.9

References

Related threats