PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97730 Netgate CVE debrief

CVE-2026-97730 is a Local File Inclusion (LFI) vulnerability in Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0. An authenticated attacker can execute arbitrary PHP code by modifying Dashboard settings and writing arbitrary files to the pfSense firewall system. This vulnerability allows for potential arbitrary PHP code execution on pfSense systems, possible escalation of privileges for authenticated attackers, and risk of compromise of pfSense firewalls and associated networks.

Vendor
Netgate
Product
pfSense Plus
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-26
Advisory published
2026-09-25
Advisory updated
2026-09-26

Who should care

pfSense administrators, security teams, and IT professionals responsible for pfSense deployments should assess exposure and apply patches or mitigations as needed. These stakeholders must verify affected versions, review compensating controls, and monitor for suspicious activity. They should also prioritize patching and verify file system integrity to mitigate potential risks.

Why it matters

CVE-2026-97730 is a high-severity LFI vulnerability in Netgate pfSense Plus and CE, allowing authenticated attackers to execute arbitrary PHP code. pfSense administrators should assess exposure, apply patches, and monitor for suspicious activity.

  • Potential arbitrary PHP code execution on pfSense systems
  • Possible escalation of privileges for authenticated attackers
  • Risk of compromise of pfSense firewalls and associated networks
  • Need for verification of affected versions and exposure

Technical summary

The Dashboard widget sequence data handling in Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0 is vulnerable to LFI. An authenticated attacker can execute arbitrary PHP code by submitting a crafted widget sequence value containing a path traversal payload. The vulnerability exists in the index.php file of the Dashboard widget sequence data handling. This allows potential arbitrary PHP code execution on pfSense systems and possible escalation of privileges for authenticated attackers. Administrators should assess exposure and apply patches or mitigations as needed.

Defensive priority

High priority for pfSense administrators to assess exposure and apply patches

Recommended defensive actions

  • Assess exposure by checking pfSense versions and configurations
  • Apply patches or upgrades to affected systems
  • Monitor for suspicious Dashboard activity
  • Verify file system integrity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the LFI vulnerability. Specific version details and exploitation scope require verification from official sources. The vulnerability has a CVSS score of 8.5 and is considered high-severity. Administrators should verify affected versions and exposure. Official references include CVE Program records and NIST NVD entries.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97730 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97730

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97730 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97730

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.