Description
pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface. An attacker who controls a PTR record and generates sufficient traffic to appear as a top talker can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface, enabling account creation and arbitrary OS command execution.
Published: 2026-08-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stored cross‑site scripting flaw in the Traffic Graphs top‑talkers feature allows an attacker who controls a PTR record and can generate sufficient traffic to appear as a top talker to inject arbitrary JavaScript into the administrator’s browser. The injected script runs in the context of the authenticated admin session and can be used to create new firewall accounts and execute arbitrary operating‑system commands through the management interface.

Affected Systems

The vulnerability affects Netgate’s pfSense CE versions up to 2.8.1 and pfSense Plus versions prior to 26.07. Any system running these releases is susceptible if an attacker can manipulate reverse‑DNS PTR records for IP addresses that generate high traffic.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity; no EPSS data is available and the issue is not listed in CISA KEV, suggesting a low likelihood of widespread exploitation. An attacker must control a PTR record, generate traffic to rank as a top talker, and lure an administrator to the web interface. While the attack requires some control over DNS or the IP space of the victim, the impact, if successful, is the compromise of the firewall’s administrative session, privileged enrolment of new users, and the execution of arbitrary system commands.

Generated by OpenCVE AI on August 20, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade pfSense CE to version 2.9.0 or later.
  • Upgrade pfSense Plus to version 26.07 or later.
  • Disable or block malicious PTR records and limit high‑traffic activity from suspicious IP addresses until the update is applied.

Generated by OpenCVE AI on August 20, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Netgate
Netgate pfsense Ce
Netgate pfsense Plus
Vendors & Products Netgate
Netgate pfsense Ce
Netgate pfsense Plus

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface. An attacker who controls a PTR record and generates sufficient traffic to appear as a top talker can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface, enabling account creation and arbitrary OS command execution.
Title pfSense Plus/CE Stored XSS via Traffic Graphs PTR Record
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Netgate Pfsense Ce Pfsense Plus
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-25T13:56:21.621Z

Reserved: 2026-07-28T16:06:49.773Z

Link: CVE-2026-67189

cve-icon Vulnrichment

Updated: 2026-08-25T13:56:17.439Z

cve-icon NVD

Status : Received

Published: 2026-08-19T20:17:20.740

Modified: 2026-08-25T14:16:53.180

Link: CVE-2026-67189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T12:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')