PT-2026-98345 · Netgate · Pfsense Ce+1
CVE-2026-97730
·
Published
2026-09-25
·
Updated
2026-09-26
CVSS v3.1
8.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pfSense Plus versions prior to 26.07
pfSense CE versions prior to 2.9.0
Description
A Local File Inclusion (LFI) issue exists in the Dashboard widget sequence data handling. An authenticated attacker with permissions to modify Dashboard settings and the ability to write arbitrary files to the system can execute arbitrary PHP code. By submitting a crafted widget sequence value containing a path traversal payload to the 'index.php' endpoint, the system can be forced to read and execute an arbitrary PHP file as if it were a standard widget.
Recommendations
Update pfSense Plus to version 26.07 or later.
Update pfSense CE to version 2.9.0 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pfsense Ce
Pfsense Plus