PatchSiren debrief for CVE-2026-49132: OPNsense stored cross-site scripting vulnerability via certificate description field allows authenticated attackers to inject arbitrary HTML or JavaScript, enabling session hijacking or credential theft in the Dashboard. System administrators and security teams should assess exposure and prioritize remediation. The vulnerability exists in OPNsense before 26.1.9, and [truncated]
A stored cross-site scripting vulnerability exists in OPNsense before version 26.1.9. Authenticated attackers with firewall rule management privileges can inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule description field via the filter API endpoint. The unsanitized description value is persisted and later rendered through the default cell formatter in opnsense_bootgrid.js, w [truncated]