PT-2026-98345 · Netgate · Pfsense Ce+1

CVE-2026-97730

·

Published

2026-09-25

·

Updated

2026-09-26

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pfSense Plus versions prior to 26.07 pfSense CE versions prior to 2.9.0
Description A Local File Inclusion (LFI) issue exists in the Dashboard widget sequence data handling. An authenticated attacker with permissions to modify Dashboard settings and the ability to write arbitrary files to the system can execute arbitrary PHP code. By submitting a crafted widget sequence value containing a path traversal payload to the 'index.php' endpoint, the system can be forced to read and execute an arbitrary PHP file as if it were a standard widget.
Recommendations Update pfSense Plus to version 26.07 or later. Update pfSense CE to version 2.9.0 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97730

Affected Products

Pfsense Ce
Pfsense Plus