PatchSiren

Deciso B.V. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Deciso B.V. CVE published 2026-08-03

CVE-2026-49132

PatchSiren debrief for CVE-2026-49132: OPNsense stored cross-site scripting vulnerability via certificate description field allows authenticated attackers to inject arbitrary HTML or JavaScript, enabling session hijacking or credential theft in the Dashboard. System administrators and security teams should assess exposure and prioritize remediation. The vulnerability exists in OPNsense before 26.1.9, and [truncated]

MEDIUM Deciso B.V. CVE published 2026-08-03

CVE-2026-49131

A stored cross-site scripting vulnerability exists in OPNsense before version 26.1.9. Authenticated attackers with firewall rule management privileges can inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule description field via the filter API endpoint. The unsanitized description value is persisted and later rendered through the default cell formatter in opnsense_bootgrid.js, w [truncated]