Cross-site scripting in OPNsense - #VU139369

 

Cross-site scripting in OPNsense - #VU139369

Published: July 26, 2026


Vulnerability identifier: #VU139369
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the victim's browser within the WebGUI origin.

The vulnerability exists due to cross-site scripting in the IDS rule details view when rendering Suricata rule reference:url metadata as HTML. A remote user can control a trusted or enabled ruleset source to execute arbitrary script in the victim's browser within the WebGUI origin.

User interaction is required to open the installed rule details dialog.


Affected software

OPNsense

Remediation

Install security update from vendor's website.

OPNsense - update to 26.7.1

External References

Related Security Bulletins