Stored XSS Vulnerability in pfSense Plus and CE Products
CVE-2026-56126

5.1MEDIUM

Key Information:

Vendor

Netgate

Vendor
CVE Published:
3 September 2026

What is CVE-2026-56126?

An XSS vulnerability in pfSense Plus and CE allows authenticated users with monitoring privileges to inject arbitrary JavaScript code through unsanitized graph configuration parameters in the Status Monitoring interface. This occurs when various POST parameters are concatenated into the global pfSense XML configuration, which is later rendered unsanitized in a JavaScript context. As a result, any maliciously constructed input can execute in the browsers of all users accessing the Status Monitoring page, creating a potential attack vector for user data compromise.

Affected Version(s)

pfSense CE 0

pfSense Plus 0 < 26.07

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams from Pellera Technologies
VulnCheck
.