Cross-site scripting in OPNsense - #VU139368

 

Cross-site scripting in OPNsense - #VU139368

Published: July 26, 2026


Vulnerability identifier: #VU139368
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the victim's browser within the WebGUI origin.

The vulnerability exists due to cross-site scripting in the dashboard announcements widget when rendering feed-supplied description and link data into HTML. A remote user can control a trusted RSS feed source to execute arbitrary script in the victim's browser within the WebGUI origin.

User interaction is required to open the dashboard with the Announcements widget enabled.


Affected software

OPNsense

Remediation

Install security update from vendor's website.

OPNsense - update to 26.7.1

External References

Related Security Bulletins