-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= pfSense-SA-26_19.webgui Security Advisory pfSense Topic: Potential information disclosure during configuration encryption and decryption operations Category: pfSense Base System Module: webgui Announced: 2026-08-13 Credits: @lujiefsi Affects: pfSense Plus software versions < 26.07 pfSense CE software versions <= 2.8.1 Corrected: 2026-07-20 17:42:59 UTC (pfSense Plus master, 26.10) 2026-07-20 17:49:44 UTC (pfSense Plus plus-RELENG_26_07, 26.07) 2026-07-20 17:42:59 UTC (pfSense CE master, 2.9.0) 0. Revision History v1.0 2026-08-13 Initial SA draft I. Background pfSense® software is a free network firewall distribution based on the FreeBSD operating system. The pfSense software distribution includes third- party free software packages for additional functionality, and provides most of the functionality of common commercial firewalls. pfSense® Plus is the productized version of pfSense software from Netgate®, previously referred to as pfSense Factory Edition (FE). It is available to Netgate appliance and CSP customers. The majority of users of pfSense software have never installed or used a stock FreeBSD system. Unlike similar GNU/Linux-based firewall distributions, there is no need for any UNIX knowledge. The command line is never used, and there is no need to ever manually edit any rule sets. Instead, pfSense software includes a web interface for the configuration of all included components. Users familiar with commercial firewalls will quickly understand the web interface, while those unfamiliar with commercial-grade firewalls may encounter a short learning curve. II. Problem Description When encrypting or decrypting data, the code in crypt.inc uses the passphrase in openssl command line parameters. Though the processes are short-lived, there is a potential the passphrase could be observed by someone using various methods to view the process list. This problem is present on pfSense Plus version 26.03.1, pfSense CE version 2.8.1, and earlier versions of both. III. Impact The configuration encryption and decryption process can occur during manual backups, restores, or automatically via AutoConfigBackup. An attacker with sufficient access to view the process list via any method, such as diag_system_activity.php or status.php, may be able to see the configuration encryption passphrase if they happen to view the process list while the encryption or decryption is occurring. Note that this DOES NOT enable the attacker to obtain a copy of either the encrypted or decrypted configuration, only the passphrase. If the attacker were to obtain the passphrase and also obtain an encrypted copy of the configuration by some other means, they may be able to see portions of the configuration data they otherwise would not have access to view. IV. Workaround To help mitigate the problem on older releases, use one or more of the following: * Limit access to the affected pages to trusted administrators only. V. Solution Users can upgrade to pfSense Plus software version 26.07 or later, or pfSense CE software versions after 2.8.1 when available. This upgrade may be performed in the web interface or from the console. See https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide.html Users on pfSense Plus version 26.03.1 and pfSense CE version 2.8.1 may apply the fix from the recommended patches list in the System Patches package after installing or updating the System Patches package. Users may also manually apply the relevant changes using the System Patches package on earlier versions, or by manually making similar changes to the affected files if the patches do not apply directly. See https://docs.netgate.com/pfsense/en/latest/development/system-patches.html VI. Correction details The following list contains the correction revision commit ID for each affected item. Branch/path Revision - - ------------------------------------------------------------------------- plus/plus-master a0b135f75987dd015b9973a3a91c14556d227d2a plus/plus-RELENG_26_07 e08a9624066b7dd874ff6ea5a224e7eafd6c4f68 pfSense/master a0b135f75987dd015b9973a3a91c14556d227d2a - - ------------------------------------------------------------------------- VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE40XvjEU56XSUPIMdE7mH/ZIU+NoFAmp+HsEACgkQE7mH/ZIU +Nr2GxAAva6gNpW5wiQqzmK0oIMWzd7r65zcrbMyDXMYbOPxDEkY7uuYQrIj/d6V QpJs/paxr++u98N6nimb0+iah6MghDMaQodhTrlebKJa7kVBMjbxrsm+QAy6L85K 9m9v5SL9ZWgodzWwPjdWC5sWzEXUBtW2eiDBo/g8i3qo/yQeFP0l1X96TAJ+5BkL 6XM75gXN6PQsfPPWXl6ooPfC8gYzvGRKdZux7sUS/KKU+fr8+Qxju/mq9QmA+Hpw tlf+8DktxGHsCLNDDFMQsZ5g+K35UmSEGuLxzVOtHi8zUiTNg7YWl1rBAad6JLhq 982AXJXgCBE1oIdVVWy1L3ZLGfz5L5JPnzCzQErRvhpwIuLtqfLL7nQ9Zsh4/nDo R3oMz46AhbJv0gBDelyIs5TW3OzTqF9HPPYANetv1aVmcfH6goL6A9Vr+VhpC9fg SHaL3jH2pnVENQIshtAPWdwytk4Ta9YUUmXY67Wm3DHNNPMBujylaQkXN/fPvqX7 GFwbAKsJQv1zYX4VZ7TRF9S7BXFxGy6686thg0soG8jRswWNQNqRkyXiKvW837z7 ibw3fG1RhHiLa0RCqgNDfkioR5t8k+v8GnhZWCnJ6VtbZE7JGoTCHDHodymUVtvr eVCyH07EAf30jebwQvTZYVAm4SNNMu/LuNSkYvuGL6NbRU93E4g= =P0S/ -----END PGP SIGNATURE-----