PT-2026-78647 · Netgate · Pfsense Ce+1

·

CVE-2026-67189

·

Published

2026-08-19

·

Updated

2026-08-25

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions pfSense Plus versions prior to 26.07 pfSense CE versions prior to 2.8.2
Description A stored cross-site scripting issue exists in the Traffic Graphs top-talkers feature. The system incorporates PTR records (pointers used in reverse DNS lookups to map an IP address to a hostname) returned by reverse DNS lookups into AJAX responses without sanitization. These records are then rendered as HTML through a DOM sink in the administrator interface. An attacker controlling a PTR record who generates enough traffic to be listed as a top talker can execute arbitrary JavaScript in an administrator's browser. This allows the attacker to access the authenticated session context and the firewall management interface, potentially leading to the creation of new accounts and arbitrary OS command execution.
Recommendations Update pfSense Plus to version 26.07 or later. Update pfSense CE to version 2.8.2 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67189

Affected Products

Pfsense Ce
Pfsense Plus