Cross-site scripting in OPNsense - #VU142555

 

Cross-site scripting in OPNsense - #VU142555

Published: August 14, 2026


Vulnerability identifier: #VU142555
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.

The vulnerability exists due to cross-site scripting in the IDS Policy Editor metadata property renderer when constructing select and option HTML from ruleset metadata. A remote privileged user can provide specially crafted metadata property names or values through a controlled ruleset source to execute arbitrary JavaScript in the victim\'s browser.

User interaction is required to open the IDS policy editor, and the generated handler may be triggered automatically by the page\'s own change event. Exploitation requires control or compromise of an enabled ruleset source.


Affected software

OPNsense

Remediation

Install security update from vendor's website.

OPNsense - update to 26.7.2

External References

Related Security Bulletins