Cross-site scripting in OPNsense - #VU142552

 

Cross-site scripting in OPNsense - #VU142552

Published: August 14, 2026


Vulnerability identifier: #VU142552
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.

The vulnerability exists due to cross-site scripting in Firewall Alias category tooltip rendering when constructing HTML attributes from stored category names. A remote privileged user can rename a referenced category with a specially crafted value to execute arbitrary JavaScript in the victim\'s browser.

User interaction is required to hover the category icon, and exploitation additionally requires that the category already be assigned to an alias visible in the target view.


Affected software

OPNsense

Remediation

Install security update from vendor's website.

OPNsense - update to 26.7.2

External References

Related Security Bulletins