-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= pfSense-SA-26_21.webgui Security Advisory pfSense Topic: Stored XSS in Traffic Graphs Display option Category: pfSense Base System Module: webgui Announced: 2026-08-13 Credits: BENDIB MOHAMED ANIS CVE ID: CVE-2026-67189 Affects: pfSense Plus software versions < 26.07 pfSense CE software versions <= 2.8.1 Corrected: 2026-07-29 14:24:05 UTC (pfSense Plus master, 26.10) 2026-07-29 14:32:14 UTC (pfSense Plus plus-RELENG_26_07, 26.07) 2026-07-29 14:24:05 UTC (pfSense CE master, 2.9.0) 0. Revision History v1.0 2026-08-13 Initial SA draft I. Background pfSense® software is a free network firewall distribution based on the FreeBSD operating system. The pfSense software distribution includes third- party free software packages for additional functionality, and provides most of the functionality of common commercial firewalls. pfSense® Plus is the productized version of pfSense software from Netgate®, previously referred to as pfSense Factory Edition (FE). It is available to Netgate appliance and CSP customers. The majority of users of pfSense software have never installed or used a stock FreeBSD system. Unlike similar GNU/Linux-based firewall distributions, there is no need for any UNIX knowledge. The command line is never used, and there is no need to ever manually edit any rule sets. Instead, pfSense software includes a web interface for the configuration of all included components. Users familiar with commercial firewalls will quickly understand the web interface, while those unfamiliar with commercial-grade firewalls may encounter a short learning curve. II. Problem Description A potential stored Cross-Site Scripting (XSS) vulnerability was identified in the Display option for the Traffic Graph host bandwidth table on status_graphs.php. The page at status_graphs.php displays a table of hosts currently consuming bandwidth. By default, this list displays IP addresses. Optionally, this table can instead display fully qualified domain names and hostnames as well as descriptions from DNS Resolver Host Overrides, DNS Forwarder Host Overrides, and DHCP Static Mappings. The page displays these descriptions and hostnames without encoding. This problem is present on pfSense Plus version 26.03.1, pfSense CE version 2.8.1, and earlier versions of both. III. Impact Though there are at least four potential paths which can result in XSS, only one is currently known to be viable. The only viable method is: * An attacker has access to the GUI and the DNS Resolver or DNS Forwarder page to create or edit Host Override entries * An attacker creates or edits a DNS Resolver or DNS Forwarder Host Override to contain an XSS payload in its Description * An administrator has the Traffic Graphs page configured with the non-default option to display Descriptions * An administrator is viewing the Traffic Graphs page * The attacker sends enough traffic to be visible in the table from the host address in the override If all of those conditions are met, then it could result in XSS. Arbitrary JavaScript could be executed in the user's browser. The user's session cookie or other information from the session may be compromised. Additional Notes: While displaying hostnames is a possible means to trigger the issue, FreeBSD libraries prevent resolving names with such payloads via PTR records. Placing the payload manually into /etc/hosts can trigger the problem, but there is no way for GUI users to do that via the GUI without full adminstrator privileges. Displaying descriptions from DHCP Static Mappings is also possible in theory, however, that feature was not functional due to a separate bug (#19679). IV. Workaround To help mitigate the problem on older releases, use one or more of the following: * Do not configure the Traffic Graphs Display option with a value of Descriptions * Do not log into the firewall with the same browser used for non- administrative web browsing. V. Solution Users can upgrade to pfSense Plus software version 26.07 or later, or pfSense CE software versions after 2.8.1 when available. This upgrade may be performed in the web interface or from the console. See https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide.html Users on pfSense Plus version 26.03.1 and pfSense CE version 2.8.1 may apply the fix from the recommended patches list in the System Patches package after installing or updating the System Patches package. Users may also manually apply the relevant changes using the System Patches package on earlier versions, or by manually making similar changes to the affected files if the patches do not apply directly. See https://docs.netgate.com/pfsense/en/latest/development/system-patches.html VI. Correction details The following list contains the correction revision commit ID for each affected item. Branch/path Revision - - ------------------------------------------------------------------------- plus/plus-master fd2e6933ee81105246e55be5da0ee2295d30fad1 plus/plus-RELENG_26_07 ee2a572582ad62838eaf95e93af293ddb00446d5 pfSense/master fd2e6933ee81105246e55be5da0ee2295d30fad1 - - ------------------------------------------------------------------------- VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE40XvjEU56XSUPIMdE7mH/ZIU+NoFAmp+HskACgkQE7mH/ZIU +NoyEw//StC2VoGQInS/dfmGqkPjhkc4fWTW4snLxjDGrMDPaJKIRxz0UgGgjCHm YNnTDSzf4w8BFL4QZyaLIp+l9GonvNTjt2de5ts6C5zAG3l93fBEmqA02O1q6jGk g1fIfWqz32Uj526wHrniF8t9+zusHXvm23MPkjIr6jyLSNDyKpbzJo9tFUYh2AJb O6MlPC5oijx/kpEqD9MeK0MYExyKjN+Ei+j3F371CjTuDFEPwY4A0yRpBNuc/VE+ Nv0SqHghQn2t1Doe7tB47k+dmlOZw4Up+PajP5FfK9S5f05vYNfO/THTJ3Ocgg+Z UqTHerl4ts3Z8N2FHN6ooY5kBo+FBt2ZwZcn1Yds/aTBvMYvgonpYrbAyz09ckb5 BK0BevZLQt12FUQ7048fDB/L06IWZUc/Yk/qONabAYEQzk7e9Z6xbj7633hkqQdx MTQq/MEED9LJBYnR9ja1jxL0NIUGfrd/VpmKDpA+Tv9V14FHc4zCBT0YxjUaULCb QjRuq/qOs9fbyBkvg1lVWfZMWMN/hSMi+RUJWC3lbPvRljpK4ncU6WzXQUoLaM9C PKO7fE27bVZl8zrCbVGbqccRxiI9GisKcqnMfWHPW+zpKjm3YkASbLsWNreDk6oz cQpr4v9+n1Fl1xRJMYO7erczTnR/osLlB7Ro2Wxm4sQzjxIR7fM= =0lJF -----END PGP SIGNATURE-----