Local File Inclusion Vulnerability in pfSense Plus and pfSense CE Products by Netgate
CVE-2026-97730
8.5HIGH
What is CVE-2026-97730?
In pfSense Plus versions prior to 26.07 and pfSense CE versions before 2.9.0, a Local File Inclusion (LFI) vulnerability exists in the handling of widget sequence data within the Dashboard. An authenticated attacker with permissions to alter Dashboard settings can exploit this flaw to execute arbitrary PHP code. By submitting a specially crafted widget sequence value that contains a path traversal payload, an attacker may trick the Dashboard into reading and executing unauthorized PHP files. This poses significant security risks as it allows attackers to run malicious code on the pfSense firewall system.
Affected Version(s)
pfSense CE FreeBSD 0 < 2.9.0
pfSense Plus FreeBSD 0 < 26.07
