A vulnerability marked as problematic has been reported in Deciso B.V. OPNsense up to 26.1.8. This impacts an unknown function of the file Certificates.js of the component Dashboard Certificates widget. This manipulation of the argument certificate description causes cross site scripting.

The identification of this vulnerability is CVE-2026-49132. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.