Cross-site scripting in OPNsense - #VU139366

 

Cross-site scripting in OPNsense - #VU139366

Published: July 26, 2026


Vulnerability identifier: #VU139366
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the victim's browser within the WebGUI origin.

The vulnerability exists due to cross-site scripting in the trust revocation CRL description handling in /ui/trust/crl when rendering a stored CRL description into the CRL edit tab label. A remote user can store a crafted CRL description to execute arbitrary script in the victim's browser within the WebGUI origin.

User interaction is required to open the CRL edit row.


Affected software

OPNsense

Remediation

Install security update from vendor's website.

OPNsense - update to 26.7.1

External References

Related Security Bulletins