-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= pfSense-SA-26_09.packages Security Advisory pfSense Topic: Stored XSS in Status Monitoring base system package Category: pfSense Base System Packages Module: Status_Monitoring Announced: 2026-08-13 Credits: Alex Williams from Pellera Technologies CVE ID: CVE-2026-56126 Affects: pfSense Plus software versions < 26.07 containing pfSense-Status_Monitoring-php85 base package < 1.9 pfSense CE software versions <= 2.8.1 containing pfSense-Status_Monitoring-php83 base package < 1.8_10 Corrected: 2026-06-30 19:53:23 UTC factory-ports/plus-devel, v1.9 for Plus 26.10 2026-07-01 15:34:46 UTC factory-ports/plus-RELENG_26_07, v1.9 for Plus 26.07 2026-07-01 15:35:05 UTC factory-ports/plus-RELENG_26_03_1, v1.9 for Plus 26.03.1 2026-06-30 19:53:23 UTC FreeBSD-ports/devel, v1.9 for CE 2.9.0 2026-07-01 15:22:45 UTC FreeBSD-ports/RELENG_2_8_1, v1.8_10 for CE 2.8.1 0. Revision History v1.0 2026-08-13 Initial SA draft I. Background pfSense® software is a free network firewall distribution based on the FreeBSD operating system. The pfSense software distribution includes third- party free software packages for additional functionality, and provides most of the functionality of common commercial firewalls. pfSense® Plus is the productized version of pfSense software from Netgate®, previously referred to as pfSense Factory Edition (FE). It is available to Netgate appliance and CSP customers. The majority of users of pfSense software have never installed or used a stock FreeBSD system. Unlike similar GNU/Linux-based firewall distributions, there is no need for any UNIX knowledge. The command line is never used, and there is no need to ever manually edit any rule sets. Instead, pfSense software includes a web interface for the configuration of all included components. Users familiar with commercial firewalls will quickly understand the web interface, while those unfamiliar with commercial-grade firewalls may encounter a short learning curve. II. Problem Description A potential stored Cross-Site Scripting (XSS) vulnerability was identified in status_monitoring.php saved views. The configuration fields stored when saving a view lacked validation, and some of those values can be printed back to the user without encoding in certain circumstances, leading to a potential stored XSS. This problem is present on pfSense Plus version 26.03.1, pfSense CE version 2.8.1, and earlier versions of both. III. Impact An attacker with the ability to access status_monitoring.php and change the configuration could store a view containing specially crafted values which trigger an XSS on subsequent visits to the page. Arbitrary JavaScript could be executed in the user's browser. The user's session cookie or other information from the session may be compromised. IV. Workaround To help mitigate the problem on older releases, use one or more of the following: * Limit access to the affected pages to trusted administrators only. * Do not log into the firewall with the same browser used for non- administrative web browsing. V. Solution Though the pfSense-Status_Monitoring package is included in base installations of pfSense software, it may be updated independently. Version 1.9 contains the corrected files, as well as version 1.8_10 for pfSense CE software version 2.8.1. Systems upgraded in-place to current versions of pfSense Plus or CE software after the corrected version of pfSense-Status_Monitoring was made available will already contain the fixed version. Check the version number reported by "pkg info pfSense-Status_Monitoring". If it is 1.9 or later on pfSense Plus software, or 1.8_10 or later on pfSense CE software, the installation is not affected. If the installed version of pfSense-Status_Monitoring is lower than the corrected versions, then update the pfSense-Status_Monitoring package version to the latest available version manually. From the console or SSH shell prompt, run the following commands to update the pfSense-Status_Monitoring package: pkg update pkg upgrade -yxf pfSense-Status_Monitoring\* Users can also upgrade to pfSense Plus software version 26.07 or later, or pfSense CE software versions after 2.8.1 when available. This upgrade may be performed in the web interface or from the console. See https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide.html VI. Correction details The following list contains the correction revision commit ID for each affected item. Branch/path Revision - - ------------------------------------------------------------------------- factory-ports/plus-devel 42c491e862ca2aa6edefe124cf7585791a338448 factory-ports/plus-RELENG_26_07 9d8fc94e2a340338e0df2875795a31dc67a6449e factory-ports/plus-RELENG_26_03_1 9faf68d43629e1b0eed558867b19e3499cdabc2d FreeBSD-ports/devel 42c491e862ca2aa6edefe124cf7585791a338448 FreeBSD-ports/RELENG_2_8_1 d30a776b11e6d6ed522cf72d54246ac248dad633 - - ------------------------------------------------------------------------- VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE40XvjEU56XSUPIMdE7mH/ZIU+NoFAmp+HpkACgkQE7mH/ZIU +Nq2lRAA4TybRdzts5otXVFw/K8ff9xuJ2hpkQW1htzRIR9CvTbCBEqpxxhlq/wM MShBWikys0fLRvX1v+PKPSTfuuwew+2NxRDYRc9WojfrownZu4ZRnaIafOAWn/1o 2TS/cNyiLOD6vroIv9HDXqyQo3phvaz36uQ4eVWXj+4cAsdm/m8/KqA1zIO0wqev lA83dda/qReO0SI49wmreOINycBgYwE4Oa6L2u8AxT5TxkuEFNoaH1luVVA+yPEZ QaSYwTKBnVjzowxw+RJKY8G191CKLsdUuExwSk/8WSMrkSQSLMaZIo3/SDdgD+Di kGrCpSRA4yJgf2fcOy7fIccWcnG2UInehgyPc3uD9xoRsXA+ta8pR7q0IgFFeDYM AE7rAuSrLChBp5jXwE1llNRuyEWi7ObrQimcf2VEF5bUI9GDCgLYrsfd6jr0RNhK OjuHCyEvx1aB0OfkmFsVUB45rAeLFvptYTgN3j2HmSB2EYsieLKRku8b0z2SBbnc ILoBpaOA0xXV4BXyTwc9P/wFwVNBrQ3FvIkBDrNsKoWXFzsXHX2bw1mqKh66AuHV hBWBgBXWQRbg+TO/+9MQF8QmLhTOwtR1k874SheNHHjpaD/d+rGhuQdCKTIScbsV 7YW6SSr7My2BJGKrxwwM3UMZx0udZ7YI/doxPe1kcYDK2tGUiYo= =YFoJ -----END PGP SIGNATURE-----