๐Ÿ” CVE Alert

CVE-2026-56127

MEDIUM 5.4

pfSense Plus < 26.07 / CE < 2.9.0 Stored XSS via firewall_rules_edit.php

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter in /firewall_rules_edit.php. The firewall rule description is stored in the pfSense XML configuration with only backslash-escaping applied and no HTML sanitization, then rendered without encoding in the firewall log table in /status_logs_filter.php. The payload executes in the browser of any user with the Status: Logs: Firewall privilege who views the affected log entries.

CWE CWE-79
Vendor netgate
Product pfsense plus
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for netgate pfsense plus

Be the first to know when new medium vulnerabilities affecting netgate pfsense plus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Netgate / pfSense Plus
0 < 26.07
Netgate / pfSense CE
0 < 2.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.netgate.com: https://docs.netgate.com/downloads/pfSense-SA-26_10.webgui.asc docs.netgate.com: https://docs.netgate.com/pfsense/en/latest/releases/26-07.html docs.netgate.com: https://docs.netgate.com/pfsense/en/latest/releases/2-9-0.html vulncheck.com: https://www.vulncheck.com/advisories/pfsense-plus-ce-stored-xss-via-firewall-rules-edit-php

Credits

Alex Williams from Pellera Technologies VulnCheck