๐Ÿ” CVE Alert

CVE-2026-97730

HIGH 8.5
CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
0th

In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write arbitrary files to the pfSense firewall system (e.g., /tmp/test.widget.php) can submit a crafted widget sequence value containing a path traversal payload (e.g., ../../../../../../../../../../../tmp/test). The Dashboard will subsequently read and execute the arbitrary PHP file as if it were a standard widget.

CWE CWE-24
Vendor netgate
Product pfsense plus
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for netgate pfsense plus

Be the first to know when new high vulnerabilities affecting netgate pfsense plus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Netgate / pfSense Plus
0 < 26.07
Netgate / pfSense CE
0 < 2.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
redmine.pfsense.org: https://redmine.pfsense.org/issues/16947 docs.netgate.com: https://docs.netgate.com/downloads/pfSense-SA-26_18.webgui.asc redmine.pfsense.org: https://redmine.pfsense.org/attachments/7146 docs.netgate.com: https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide.html