Stored XSS Vulnerability in pfSense Firewall Management
CVE-2026-56127
5.1MEDIUM
What is CVE-2026-56127?
An authorization flaw in pfSense versions prior to 26.07 (Plus) and 2.9.0 (CE) enables authenticated users with permission to edit firewall rules to inject arbitrary JavaScript via the 'descr' parameter in the firewall rules edit page. The injected payload is stored in the pfSense XML configuration with minimal escaping and is rendered without HTML sanitization in the logs, making it possible for other users with access to view these logs to execute the embedded script within their browsers.
Affected Version(s)
pfSense CE 0
pfSense Plus 0 < 26.07
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Williams from Pellera Technologies
VulnCheck
