Stored XSS Vulnerability in pfSense Plus and CE Products
CVE-2026-56126
5.1MEDIUM
What is CVE-2026-56126?
An XSS vulnerability in pfSense Plus and CE allows authenticated users with monitoring privileges to inject arbitrary JavaScript code through unsanitized graph configuration parameters in the Status Monitoring interface. This occurs when various POST parameters are concatenated into the global pfSense XML configuration, which is later rendered unsanitized in a JavaScript context. As a result, any maliciously constructed input can execute in the browsers of all users accessing the Status Monitoring page, creating a potential attack vector for user data compromise.
Affected Version(s)
pfSense CE 0
pfSense Plus 0 < 26.07
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Williams from Pellera Technologies
VulnCheck
