SB20260814122 - Multiple vulnerabilities in OPNsense



SB20260814122 - Multiple vulnerabilities in OPNsense

Published: August 14, 2026

Security Bulletin ID SB20260814122
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 vulnerabilities.


1) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary script code in a victim\'s browser.

The vulnerability exists due to cross-site scripting in the wireless EAP selectors on interfaces.php when rendering certificate and CA descriptions. A remote privileged user can inject crafted HTML or script into the descr field to execute arbitrary script code in a victim\'s browser.

User interaction is required to load the wireless interface configuration page where the unescaped descriptions are rendered.


2) Command injection (CVE-ID: N/A)

CWE-ID: CWE-77 - Command injection

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary OpenVPN management protocol commands.

The vulnerability exists due to command injection in the OpenVPN session kill endpoint and backend kill_session.py script when handling a crafted session_id parameter containing newline characters. A remote privileged user can send a specially crafted request to execute arbitrary OpenVPN management protocol commands.

The injected commands are written to the OpenVPN management unix socket as root, and exploitation can terminate, restart, or otherwise control the VPN daemon. An authenticated VPN peer may also reach the same injection path through a crafted certificate common name when an operator kills its session.


3) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.

The vulnerability exists due to cross-site scripting in Firewall Alias category tooltip rendering when constructing HTML attributes from stored category names. A remote privileged user can rename a referenced category with a specially crafted value to execute arbitrary JavaScript in the victim\'s browser.

User interaction is required to hover the category icon, and exploitation additionally requires that the category already be assigned to an alias visible in the target view.


4) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.

The vulnerability exists due to cross-site scripting in IPsec SPD description tooltip rendering when constructing HTML attributes from stored connection or child descriptions. A remote privileged user can supply a specially crafted description value to execute arbitrary JavaScript in the victim\'s browser.

User interaction is required to hover the information icon, and exploitation additionally requires a matching runtime SPD row that maps to the stored description. The SAD renderer is described as static-equivalent but was not separately confirmed.


5) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.

The vulnerability exists due to cross-site scripting in Traffic Shaper relation description tooltip rendering in Firewall Rules when constructing HTML attributes from stored shaper descriptions. A remote privileged user can modify a referenced shaper object\'s description with a specially crafted value to execute arbitrary JavaScript in the victim\'s browser.

User interaction is required to hover the gear icon, and exploitation additionally requires that a firewall rule already reference the affected pipe or queue.


6) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.

The vulnerability exists due to cross-site scripting in the IDS Policy Editor metadata property renderer when constructing select and option HTML from ruleset metadata. A remote privileged user can provide specially crafted metadata property names or values through a controlled ruleset source to execute arbitrary JavaScript in the victim\'s browser.

User interaction is required to open the IDS policy editor, and the generated handler may be triggered automatically by the page\'s own change event. Exploitation requires control or compromise of an enabled ruleset source.


Remediation

Install update from vendor's website.