Stored XSS Vulnerability in pfSense Firewall Management
CVE-2026-56127

5.1MEDIUM

Key Information:

Vendor

Netgate

Vendor
CVE Published:
3 September 2026

What is CVE-2026-56127?

An authorization flaw in pfSense versions prior to 26.07 (Plus) and 2.9.0 (CE) enables authenticated users with permission to edit firewall rules to inject arbitrary JavaScript via the 'descr' parameter in the firewall rules edit page. The injected payload is stored in the pfSense XML configuration with minimal escaping and is rendered without HTML sanitization in the logs, making it possible for other users with access to view these logs to execute the embedded script within their browsers.

Affected Version(s)

pfSense CE 0

pfSense Plus 0 < 26.07

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams from Pellera Technologies
VulnCheck
.