A vulnerability labeled as problematic has been found in Deciso OPNsense up to 26.1.8. This affects an unknown function of the file opnsense_bootgrid.js of the component Default Cell Formatter. The manipulation results in cross site scripting.

This vulnerability was named CVE-2026-49131. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.