-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= pfSense-SA-26_10.webgui Security Advisory pfSense Topic: Stored XSS in Firewall Log inline rule descriptions Category: pfSense Base System Module: webgui Announced: 2026-08-13 Credits: Alex Williams from Pellera Technologies CVE ID: CVE-2026-56127 Affects: pfSense Plus software versions < 26.07 pfSense CE software versions <= 2.8.1 Corrected: 2026-07-01 18:34:01 UTC (pfSense Plus master, 26.10) 2026-07-01 18:48:41 UTC (pfSense Plus plus-RELENG_26_07, 26.07) 2026-07-01 18:34:01 UTC (pfSense CE master, 2.9.0) 0. Revision History v1.0 2026-08-13 Initial SA draft I. Background pfSense® software is a free network firewall distribution based on the FreeBSD operating system. The pfSense software distribution includes third- party free software packages for additional functionality, and provides most of the functionality of common commercial firewalls. pfSense® Plus is the productized version of pfSense software from Netgate®, previously referred to as pfSense Factory Edition (FE). It is available to Netgate appliance and CSP customers. The majority of users of pfSense software have never installed or used a stock FreeBSD system. Unlike similar GNU/Linux-based firewall distributions, there is no need for any UNIX knowledge. The command line is never used, and there is no need to ever manually edit any rule sets. Instead, pfSense software includes a web interface for the configuration of all included components. Users familiar with commercial firewalls will quickly understand the web interface, while those unfamiliar with commercial-grade firewalls may encounter a short learning curve. II. Problem Description A potential stored Cross-Site Scripting (XSS) vulnerability was identified in status_logs_filter.php. Firewall rule descriptions are printed to the user without encoding when viewing the logs with inline rule descriptions active, either as a column or an additional row. This problem is present on pfSense Plus version 26.03.1, pfSense CE version 2.8.1, and earlier versions of both. III. Impact If an attacker with the ability to create or edit firewall rules saves a specially-crafted payload in description of a rule configured to log matches, then an administrator views the logs after a packet matches the rule, it can trigger an XSS. Arbitrary JavaScript could be executed in the user's browser. The user's session cookie or other information from the session may be compromised. IV. Workaround To help mitigate the problem on older releases, use one or more of the following: * Disable inline display of rule descriptions. * Limit access to creating or editing firewall rules. * Do not log into the firewall with the same browser used for non- administrative web browsing. V. Solution Users can upgrade to pfSense Plus software version 26.07 or later, or pfSense CE software versions after 2.8.1 when available. This upgrade may be performed in the web interface or from the console. See https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide.html Users on pfSense Plus version 26.03.1 and pfSense CE version 2.8.1 may apply the fix from the recommended patches list in the System Patches package after installing or updating the System Patches package. Users may also manually apply the relevant changes using the System Patches package on earlier versions, or by manually making similar changes to the affected files if the patches do not apply directly. See https://docs.netgate.com/pfsense/en/latest/development/system-patches.html VI. Correction details The following list contains the correction revision commit ID for each affected item. Branch/path Revision - - ------------------------------------------------------------------------- plus/plus-master 7c49f0bb23e2beac256dcf55c11810d7e5702734 plus/plus-RELENG_26_07 d8c5bfb5b41c1fb41b8c5df37173b7d79c999637 pfSense/master 7c49f0bb23e2beac256dcf55c11810d7e5702734 - - ------------------------------------------------------------------------- VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE40XvjEU56XSUPIMdE7mH/ZIU+NoFAmp+HpwACgkQE7mH/ZIU +NoK7BAAqiiKke6qmv+QTKbyiJnE7A2ztrMShmLdGtTtRdPpNfKeL/t8OC6qV3SL KzOQmpFXf/ASf7bO7hHLaexzy5G6+qpdyFks81SAZCXhysjzR46lb4oaUdLGDce3 bKJ/LgCpbEApyDyO4oi3AvMIvKNWuQRolfkMkzwlCSFsAhmgVaMD7qq0SgJRUgSE 8FmrSF4T1RHZL0kej/1RFamdnaM7TlBhZ7B4cimOUigbsaCzfLqyYePDeJQciad9 1MdZE38W3rewBPbkvkPbhdkODyWJqZ/2yH9clNdfABj2b4Z8Z9omQalV6BZUd3lf szNZTzRJale1uSHsxG8efDSL954O1rs6XVDBuWZ5UC7/Jo/0nnmr0J35sGqd6Sqn rXh5JqXM5iLVANK1B60OihBvTwTLu/p3T8YFH2lhHWL/H9pUuumcoCKoG2/eyHVp HvbW+VJCNnVBSvh3mxzfXl+kyLfarncE0lTpSCpkD0mjqCbcqTOoJtNRiHPawrJN zA2/tzFSm74onaMLSOXd2r+ARkKD2yNkRgsZP1EAmaeaPpmKr4kPk4x5cuzns49Q MZFMXV7+A1+ft/Q+AtjOTzPEZeTd9OpuyXhEaOKXQTOjexE/u9R/WGKO6lfj6djH vhqI8sgLMm53msObb79uCuuZrY/Bo6YjIbXiS0tlNMmjgffCyNQ= =bGx5 -----END PGP SIGNATURE-----