Local File Inclusion Vulnerability in pfSense Plus and pfSense CE Products by Netgate
CVE-2026-97730

8.5HIGH

Key Information:

Vendor

Netgate

Vendor
CVE Published:
25 September 2026

What is CVE-2026-97730?

In pfSense Plus versions prior to 26.07 and pfSense CE versions before 2.9.0, a Local File Inclusion (LFI) vulnerability exists in the handling of widget sequence data within the Dashboard. An authenticated attacker with permissions to alter Dashboard settings can exploit this flaw to execute arbitrary PHP code. By submitting a specially crafted widget sequence value that contains a path traversal payload, an attacker may trick the Dashboard into reading and executing unauthorized PHP files. This poses significant security risks as it allows attackers to run malicious code on the pfSense firewall system.

Affected Version(s)

pfSense CE FreeBSD 0 < 2.9.0

pfSense Plus FreeBSD 0 < 26.07

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.