-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= pfSense-SA-26_14.webgui Security Advisory pfSense Topic: Stored XSS via IPsec Phase 1 descriptions Category: pfSense Base System Module: webgui Announced: 2026-08-13 Credits: @lujiefsi Affects: pfSense Plus software versions < 26.07 pfSense CE software versions <= 2.8.1 Corrected: 2026-07-10 17:35:15 UTC (pfSense Plus master, 26.10) 2026-07-10 17:37:04 UTC (pfSense Plus plus-RELENG_26_07, 26.07) 2026-07-10 17:35:15 UTC (pfSense CE master, 2.9.0) 0. Revision History v1.0 2026-08-13 Initial SA draft I. Background pfSense® software is a free network firewall distribution based on the FreeBSD operating system. The pfSense software distribution includes third- party free software packages for additional functionality, and provides most of the functionality of common commercial firewalls. pfSense® Plus is the productized version of pfSense software from Netgate®, previously referred to as pfSense Factory Edition (FE). It is available to Netgate appliance and CSP customers. The majority of users of pfSense software have never installed or used a stock FreeBSD system. Unlike similar GNU/Linux-based firewall distributions, there is no need for any UNIX knowledge. The command line is never used, and there is no need to ever manually edit any rule sets. Instead, pfSense software includes a web interface for the configuration of all included components. Users familiar with commercial firewalls will quickly understand the web interface, while those unfamiliar with commercial-grade firewalls may encounter a short learning curve. II. Problem Description A potential stored Cross-Site Scripting (XSS) vulnerability was identified in vpn_ipsec_phase2.php when creating or editing an IPsec Phase 2 entry. When creating or editing an IPsec Phase 2 entry, the vpn_ipsec_phase2.php page displays the description of the associated IPsec Phase 1 entry without encoding. This problem is present on pfSense Plus version 26.03.1, pfSense CE version 2.8.1, and earlier versions of both. III. Impact If an attacker with the ability to create or edit IPsec Phase 1 entries on vpn_ipsec_phase1.php saves a specially-crafted payload in a Phase 1 entry description, it could trigger an XSS when creating or editing an IPsec Phase 2 entry on vpn_ipsec_phase2.php. Arbitrary JavaScript could be executed in the user's browser. The user's session cookie or other information from the session may be compromised. IV. Workaround To help mitigate the problem on older releases, use one or more of the following: * Limit access to the affected pages to trusted administrators only. * Do not log into the firewall with the same browser used for non- administrative web browsing. V. Solution Users can upgrade to pfSense Plus software version 26.07 or later, or pfSense CE software versions after 2.8.1 when available. This upgrade may be performed in the web interface or from the console. See https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide.html Users on pfSense Plus version 26.03.1 and pfSense CE version 2.8.1 may apply the fix from the recommended patches list in the System Patches package after installing or updating the System Patches package. Users may also manually apply the relevant changes using the System Patches package on earlier versions, or by manually making similar changes to the affected files if the patches do not apply directly. See https://docs.netgate.com/pfsense/en/latest/development/system-patches.html VI. Correction details The following list contains the correction revision commit ID for each affected item. Branch/path Revision - - ------------------------------------------------------------------------- plus/plus-master a8c94d9330b0d814ae87e176e74fa5d3ef53eb58 plus/plus-RELENG_26_07 74380e9c0f671c84caa7435f721c9fcfd7c4c072 pfSense/master a8c94d9330b0d814ae87e176e74fa5d3ef53eb58 - - ------------------------------------------------------------------------- VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE40XvjEU56XSUPIMdE7mH/ZIU+NoFAmp+Hq4ACgkQE7mH/ZIU +Np9IRAAslJNwujnb3xqFv2mCygvf4fRBQpWkmrfntY5UP95CAF+vgz2EyxS6zyA ezxiyPbE3SgcKQ0z4CAfzDwg89VfmoFU8VLWrglJGn3tVnldVxzZPKEAbyHyJMgw HQeX3HTpR7w9GDOMsQvT4K6PLCi2v8HQdZn+TAYuL5q7+xIKNcFFmu+B79oyJaLR y1oS6MLEuHvytVp0vKZOchRk1t7zcwjvWeOSieYWTf2dhnsa0wgWYWyR8tAb/9zp mTj2TEVi5161Oku9On/MRTnkRAdByolBRxPVaKMKe5nWxOq4jm1q00dD9CH3ECZW bGL5J+Zs5zs9lIi2CSmDfpLpfQTgsW9O7yvGJXgHlrFVn7691zbUGXJ3NZ3Qq9au 7xJLK7JUCe1S3plERwaFE4TcXnlFad38pfO7xin6/u7XoIcNhSiA5fOulZBPSS19 pDayxOMQRiTID/PoZSgMdf0Md1fkG8mWloa3Tw/iasJwdw5FvQ+p3WkW9Rm9LW05 CLm0RjtmjliBe3pV4FxaSl0DNKZ0+8hSDUdDvuMa03TC6TJEAqppyqtpids1401v 2NkqXCC6TnhehCkGn3C7U9iNeBkpjrbPhQBT3jdxMactniEefRAxQ8f9fmalFhei qo/uFLw2/AcpMr2oTXE6ZKqd4lkjNmv6dQNkIzrEQYkqPQRF7Dk= =XM1k -----END PGP SIGNATURE-----