PatchSiren cyber security CVE debrief
CVE-2026-67189 Netgate CVE debrief
The CVE-2026-67189 record describes a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature of pfSense Plus before 26.07 and pfSense CE through 2.8.1. An attacker controlling a PTR record and generating sufficient traffic can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface. This enables account creation and arbitrary OS command execution. Administrators and users of pfSense Plus and pfSense CE systems, particularly those with the Traffic Graphs feature enabled, should be aware of this vulnerability and take steps to patch or mitigate it. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM. The CVE record was published on 2026-08-19T20:17:20.740Z and has not been modified since then.
- Vendor
- Netgate
- Product
- pfSense Plus
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-25
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-25
Who should care
Administrators and users of pfSense Plus and pfSense CE systems, particularly those who have enabled the Traffic Graphs feature, should be aware of this vulnerability and take steps to patch or mitigate it. This includes reviewing system configurations, monitoring for suspicious activity, and implementing additional security measures to restrict access to the Traffic Graphs feature. Security teams and vulnerability management teams should also be aware of this vulnerability and prioritize patching or mitigation efforts accordingly. Additionally, operators and platform administrators should review the vulnerability details and assess the potential impact on their systems and networks. Vulnerability management teams should consider implementing compensating controls for exposed systems while remediation is scheduled and verified. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory and change management processes should be reviewed to ensure that affected systems are properly identified and prioritized for remediation. Monitoring and detection teams should review relevant logs and alerts to identify potential exploitation attempts. Overall, a coordinated effort is required to address this vulnerability and minimize potential risks. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM, indicating a moderate level of risk. However, the actual risk may vary depending on the specific system configurations and deployment contexts. Therefore, it is essential to carefully assess the vulnerability and implement appropriate mitigation measures to prevent exploitation. This may involve patching affected systems, implementing additional security controls, or restricting access to the Traffic Graphs feature. By taking proactive steps to address this vulnerability, organizations can reduce the risk of exploitation and protect their systems and networks from potential attacks. In addition to patching and mitigation efforts, it is also essential to review and update incident response plans to ensure that they are effective in responding to potential exploitation attempts. This
Technical summary
The stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature of pfSense Plus and pfSense CE allows an attacker who controls a PTR record and generates sufficient traffic to appear as a top talker to execute arbitrary JavaScript in an administrator's browser. This can lead to account creation and arbitrary OS command execution. The vulnerability exists in pfSense Plus before 26.07 and pfSense CE through 2.8.1. The attack involves incorporating PTR records returned by reverse DNS lookups without sanitization into AJAX responses, which are then rendered as HTML through a DOM sink in the administrator interface.
Defensive priority
Administrators of pfSense Plus and pfSense CE systems should prioritize patching the stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature.
Recommended defensive actions
- Patch pfSense Plus to version 26.07 or later
- Patch pfSense CE to version 2.8.2 or later
- Implement additional security measures to monitor and restrict access to the Traffic Graphs feature
- Consider using a web application firewall to detect and prevent cross-site scripting attacks
- Review system configurations and monitor for suspicious activity
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE description indicates that pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature. PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-67189 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-67189
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-67189 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67189
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.netgate.com/downloads/pfSense-SA-26_21.webgui.asc
-
Source reference
Unverified legacy reference
URL: https://docs.netgate.com/pfsense/en/latest/releases/2-9-0.html
-
Source reference
Unverified legacy reference
URL: https://docs.netgate.com/pfsense/en/latest/releases/26-07.html
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/pfsense-plus-ce-stored-xss-via-traffic-graphs-ptr-record
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.