CVE-2026-97730

high

Description

In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write arbitrary files to the pfSense firewall system (e.g., /tmp/test.widget.php) can submit a crafted widget sequence value containing a path traversal payload (e.g., ../../../../../../../../../../../tmp/test). The Dashboard will subsequently read and execute the arbitrary PHP file as if it were a standard widget.

References

https://redmine.pfsense.org/issues/16947

https://redmine.pfsense.org/attachments/7146

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-86509

https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide.html

https://docs.netgate.com/downloads/pfSense-SA-26_18.webgui.asc

Details

Source: Mitre, NVD

Published: 2026-09-25

Updated: 2026-09-30

Risk Information

CVSS v2

Base Score: 7.1

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.5

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.01025