-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= pfSense-SA-26_16.webgui Security Advisory pfSense Topic: Stored XSS via Dynamic DNS widget Category: pfSense Base System Module: webgui Announced: 2026-08-13 Credits: @lujiefsi Affects: pfSense Plus software versions < 26.07 pfSense CE software versions <= 2.8.1 Corrected: 2026-07-10 18:52:23 UTC (pfSense Plus master, 26.10) 2026-07-10 19:16:04 UTC (pfSense Plus plus-RELENG_26_07, 26.07) 2026-07-10 18:52:23 UTC (pfSense CE master, 2.9.0) 0. Revision History v1.0 2026-08-13 Initial SA draft I. Background pfSense® software is a free network firewall distribution based on the FreeBSD operating system. The pfSense software distribution includes third- party free software packages for additional functionality, and provides most of the functionality of common commercial firewalls. pfSense® Plus is the productized version of pfSense software from Netgate®, previously referred to as pfSense Factory Edition (FE). It is available to Netgate appliance and CSP customers. The majority of users of pfSense software have never installed or used a stock FreeBSD system. Unlike similar GNU/Linux-based firewall distributions, there is no need for any UNIX knowledge. The command line is never used, and there is no need to ever manually edit any rule sets. Instead, pfSense software includes a web interface for the configuration of all included components. Users familiar with commercial firewalls will quickly understand the web interface, while those unfamiliar with commercial-grade firewalls may encounter a short learning curve. II. Problem Description A potential stored Cross-Site Scripting (XSS) vulnerability was identified in the Dynamic DNS Dashboard widget (dyn_dns_status.widget.php) and its display of certain Dynamic DNS entry data. The widget prints the host field of Custom Dynamic DNS entries and the server field of RFC 2136 Dynamic DNS entries without encoding. This problem is present on pfSense Plus version 26.03.1, pfSense CE version 2.8.1, and earlier versions of both. III. Impact If an attacker with the ability to create or edit Dynamic DNS entries manipulates the form data and submits a specially-crafted value for the host field of a Custom instance, it could trigger an XSS when the Dynamic DNS Dashboard widget displays that instance. Additionally, if an attacker with the ability to create or edit RFC 2136 Dynamic DNS entries submits a specially-crafted value for the server field, it could trigger an XSS when the Dynamic DNS Dashboard widget displays that instance. Arbitrary JavaScript could be executed in the user's browser. The user's session cookie or other information from the session may be compromised. IV. Workaround To help mitigate the problem on older releases, use one or more of the following: * Limit access to the affected pages to trusted administrators only. * Do not log into the firewall with the same browser used for non- administrative web browsing. V. Solution Users can upgrade to pfSense Plus software version 26.07 or later, or pfSense CE software versions after 2.8.1 when available. This upgrade may be performed in the web interface or from the console. See https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide.html Users on pfSense Plus version 26.03.1 and pfSense CE version 2.8.1 may apply the fix from the recommended patches list in the System Patches package after installing or updating the System Patches package. Users may also manually apply the relevant changes using the System Patches package on earlier versions, or by manually making similar changes to the affected files if the patches do not apply directly. See https://docs.netgate.com/pfsense/en/latest/development/system-patches.html VI. Correction details The following list contains the correction revision commit ID for each affected item. Branch/path Revision - - ------------------------------------------------------------------------- plus/plus-master c4e46e94f756655f30ea92af8410f74e74b4e2f1 plus/plus-RELENG_26_07 248d55e5afd83daed9c1ddda6f815b889dc2f801 pfSense/master c4e46e94f756655f30ea92af8410f74e74b4e2f1 - - ------------------------------------------------------------------------- VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE40XvjEU56XSUPIMdE7mH/ZIU+NoFAmp+HrYACgkQE7mH/ZIU +NoV8BAAvQH/9LcYrJtQ9Xz0qXVhSJOEb3zKvCSppxtvXTYf5tgQC3QnjpjF4fFR Uco8Lq22rbOYYec0kT2FUyPGTIAr3UIbyOfbgC7nzCbqWcUNlsBQJtqv5Ts2ikHv 82SaTjFHMH9rzyLRmSM+evS8s5ulEzL0VH2TCsA21alD9EMIn2ZhwG7MmOLmtCJY nx0iO8X5daI0g4bPMZiyVxxBJe9/hSbxnz8C6isD+LxWBlgNFVzwgWUvzmLtuptZ m6kA+YrgyZmsgCgYzI9ciHQqAD7Hs+dVwYsI6M3nlbEVZGl6zPfu9phVdhB+6Uc9 f0xSanTn0hj3SF2BnReJFcWwPBFKn3rEK1htWNyzTM5MCec8+YBJJ5SQ8MK4oW7g wlh29j4iyYCdZWeinIYynBC0/maOhXhUGd8n7cEiWqFS2W+bgfKVKVMf+sosU17p dCGlRj12yn3rnvJhqqUxAHsgabRPn/AsmOgtZNdVUpyEoeEl7bbug1o8HRbOJas6 QdEHy9iztdaszE6SkaJ6EYgzEk3kd0aT00HBwG7iZ+8siYZJc6MRczO9kjqxDlrj fo8wTWQo5S9sKFeDLysx8Tg9SwtMC8NO2HUVZ5LAqsWykLIzpq8W3QcWKMR0O+va 6cW2uXi7+cU33hQH2qH2HT/KheMqqLSk67lryKlvstQhLZWVjwE= =sqlr -----END PGP SIGNATURE-----