PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-67189 Netgate CVE debrief

The CVE-2026-67189 record describes a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature of pfSense Plus before 26.07 and pfSense CE through 2.8.1. An attacker controlling a PTR record and generating sufficient traffic can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface. This enables account creation and arbitrary OS command execution. Administrators and users of pfSense Plus and pfSense CE systems, particularly those with the Traffic Graphs feature enabled, should be aware of this vulnerability and take steps to patch or mitigate it. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM. The CVE record was published on 2026-08-19T20:17:20.740Z and has not been modified since then.

Vendor
Netgate
Product
pfSense Plus
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-25
Advisory published
2026-08-19
Advisory updated
2026-08-25

Who should care

Administrators and users of pfSense Plus and pfSense CE systems, particularly those who have enabled the Traffic Graphs feature, should be aware of this vulnerability and take steps to patch or mitigate it. This includes reviewing system configurations, monitoring for suspicious activity, and implementing additional security measures to restrict access to the Traffic Graphs feature. Security teams and vulnerability management teams should also be aware of this vulnerability and prioritize patching or mitigation efforts accordingly. Additionally, operators and platform administrators should review the vulnerability details and assess the potential impact on their systems and networks. Vulnerability management teams should consider implementing compensating controls for exposed systems while remediation is scheduled and verified. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory and change management processes should be reviewed to ensure that affected systems are properly identified and prioritized for remediation. Monitoring and detection teams should review relevant logs and alerts to identify potential exploitation attempts. Overall, a coordinated effort is required to address this vulnerability and minimize potential risks. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM, indicating a moderate level of risk. However, the actual risk may vary depending on the specific system configurations and deployment contexts. Therefore, it is essential to carefully assess the vulnerability and implement appropriate mitigation measures to prevent exploitation. This may involve patching affected systems, implementing additional security controls, or restricting access to the Traffic Graphs feature. By taking proactive steps to address this vulnerability, organizations can reduce the risk of exploitation and protect their systems and networks from potential attacks. In addition to patching and mitigation efforts, it is also essential to review and update incident response plans to ensure that they are effective in responding to potential exploitation attempts. This

Technical summary

The stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature of pfSense Plus and pfSense CE allows an attacker who controls a PTR record and generates sufficient traffic to appear as a top talker to execute arbitrary JavaScript in an administrator's browser. This can lead to account creation and arbitrary OS command execution. The vulnerability exists in pfSense Plus before 26.07 and pfSense CE through 2.8.1. The attack involves incorporating PTR records returned by reverse DNS lookups without sanitization into AJAX responses, which are then rendered as HTML through a DOM sink in the administrator interface.

Defensive priority

Administrators of pfSense Plus and pfSense CE systems should prioritize patching the stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature.

Recommended defensive actions

  • Patch pfSense Plus to version 26.07 or later
  • Patch pfSense CE to version 2.8.2 or later
  • Implement additional security measures to monitor and restrict access to the Traffic Graphs feature
  • Consider using a web application firewall to detect and prevent cross-site scripting attacks
  • Review system configurations and monitor for suspicious activity
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE description indicates that pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature. PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-67189 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-67189

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-67189 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67189

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.