Cross Site Scripting Vulnerability in Netgate pfSense Software
CVE-2026-78849

5.4MEDIUM

Key Information:

Vendor

Netgate

Vendor
CVE Published:
4 September 2026

What is CVE-2026-78849?

A Cross Site Scripting (XSS) vulnerability exists in the Netgate pfSense Plus software and pfSense Community Edition, specifically in the 'captive_portal_status.widget.php' file. This issue allows remote attackers to execute arbitrary code, potentially compromising system integrity and security by injecting malicious scripts into web pages. The vulnerability affects versions of pfSense Plus up to 26.03 and pfSense CE up to 2.8.1, posing a significant risk for users who have not secured their systems against this threat.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.